Configuring IPv6 RA Guard
Configuring IPv6 RA guard includes the following steps:
- Define an RA guard whitelist using the
ipv6 raguard whitelistcommand. Add IPv6 addresses of all the sources from which the RA packets can be forwarded. You can create a maximum of 64 whitelists and each whitelist can have a maximum of 128 IPv6 address entries. - Define an RA guard policy using
the
ipv6 raguard policycommand. A RA guard policy name can be a maximum of 512 characters. You can configure a maximum of 256 RA guard policies. - Configure ports as trusted, untrusted, or host ports using the
raguardcommand in the interface configuration mode. - Associate a whitelist with an RA guard policy using the
whitelistcommand in the RA guard policy configuration mode. You can associate only one whitelist with an RA guard policy. If you do not associate a whitelist with an RA guard policy, all RA packets are dropped. - (Optional) (Only for Layer 3 devices) Associate an already defined prefix list with
the RA guard policy using the
prefix-listcommand in the RA guard policy configuration mode. You must provide the name of an IPv6 prefix list already configured using theipv6 prefix-listcommand. Associate a prefix-list with an RA guard policy using theprefix-listcommand. - (Optional) Set the preference for RA packets using the
preference-maximumcommand in the RA guard policy configuration mode. - Apply the RA guard policy to a VLAN using the
ipv6 raguard vlancommand in the global configuration mode. You can associate only one RA guard policy with a VLAN. - (Optional) Enable logging using the
loggingcommand in the RA guard policy configuration mode. If logging is enabled, you can verify the logs like RAs dropped, permitted, count for dropped packets, and reasons for the drop. Logging increases the CPU load and, for higher traffic rates, RA packets drop due to congestion if they are received at the line rate. - (Optional) Verify the RA guard configuration using the
show ipv6 raguardcommand. - (Optional) Clear the RA packet counter using the
clear ipv6 raguardcommand. - (Optional) Verify the RA packet counts using the
show ipv6 raguard countscommand. Logging has to be enabled to verify the counts.