show ipv6 raguard

Displays the Router Advertisement (RA) guard configuration details.
Syntax
show ipv6 raguard { counts | policy } { name | all }
show ipv6 raguard whitelist { number | all }
show ipv6 raguard vlan { vlan-id }
Parameters
all
When used with counts, policy, or whitelist keywords, displays the permit or drop counts for all the RA guard policies, configuration of all RA guard policies, or all the associated RA guard whitelists respectively.
counts name
Displays the RA guard permit or drop counts for the specified RA guard policy.
policy name
Displays the configuration details for the specified RA guard policy.
whitelist number
Displays information for the specified RA guard whitelist.
vlan vlan-id
Displays RA Guard information for the specified VLAN.
Modes

Privileged EXEC mode

Global configuration mode

The show ipv6 raguard counts command is applicable only when logging is enabled on the policy.

RA Guard Policies on VLANs in a Campus Fabric Configuration

Untrusted ports trap packets to the CPU and perform RA guard processing. For non-PE units, a trap rule is programmed directly on the unit where the ports are located. However, for PE units in a Campus Fabric (SPX) configuration, an untrust CB cascade rule may be created and configured for all CB SPX cascade ports.

A CB cascade rule is created in the following cases:

  • RA guard is enabled on a VLAN with PE 'untrust' ports as members.
  • RA guard is enabled on a VLAN with PE ports as members, and logging is enabled in the RA guard policy bound to the VLAN. In this case, the PE member ports can be configured as 'untrust', 'trust', or 'host'.

No CB cascade rule is created when the VLAN has CB ports but no PE ports as members.

Examples

The following example shows the RA guard drop or permit counts for all RA guard policies:

device# show ipv6 raguard counts all
POLICY: policy1
DROPPED-host port: 1
DROPPED-whitelist: 4
DROPPED-prefixlist: 1
DROPPED-max pref: 3
PASSED-trusted port: 0
PASSED-untrusted port: 0
POLICY: policy2
DROPPED-host port: 1
DROPPED-whitelist: 0
DROPPED-prefixlist: 3
DROPPED-max pref: 1
PASSED-trusted port: 0
PASSED-untrusted port: 0

The following example shows the details of a RA guard policy p1:

device# show ipv6 raguard policy p1
policy:p1
        whitelist:1

The following example shows all RA guard whitelists:

device# show ipv6 raguard whitelist all
whitelist #1 : 3 entries
        permit fe80:db8::db8:10/128
        permit fe80:db8::db8:5/128
        permit fe80:db8::db8:12/128

The following example displays output for a VLAN.

device# show ipv6 raguard vlan 320
VLAN     Policy
-----    ------
320      policy650
device#

When you use the show ipv6 raguard command to display information on RA guard policies for a VLAN with member ports that are part of an SPX system, the output indicates whether a CB cascade rule has been created and, if so, to which SPX cascade ports it applies.

The following example shows that RA guard policy10 is applied to VLAN 1001 but logging is not enabled under the policy. As a result, no cascade-port rule has been created for the cascade ports in this SPX configuration.

device(config-if-pe-e1000-44/1/15)# show ipv6 raguard vlan 1001
VLAN     Policy
-----    ------
1001     policy10
RA guard Cascade-port rule not created

The following example indicates an RA guard policy (policy20) with logging enabled is applied on VLAN 2001. The output shows the CB SPX cascade ports where it is applied.

device(config-vlan-2001)# show ipv6 raguard vlan 2001
VLAN     Policy
-----    ------
2001     policy20
RA guard Cascade-port rule created for ports: 1/1/1 2/1/15 2/1/20 3/1/20

History
Release version Command history
08.0.95 This command was modified to add the vlan option.