Example: Verifying the RA Guard Configuration

To view the RA guard packet counts, use the show ipv6 raguard counts command.

device# show ipv6 raguard counts policyB
DROPPED-host port:0
DROPPED-whitelist:3
DROPPED-prefixlist:1
DROPPED-max pref:1
DROPPED-trusted port:2
DROPPED-untrusted port:1

To verify the RA guard policy configuration, enter the show ipv6 raguard policy all command.

device# show ipv6 raguard policy all
policy:policyC
        whitelist:0
        max_pref:medium
policy:policyB
        whitelist:1

To verify the configuration of RA guard whitelists, enter the show ipv6 raguard whitelist all command.

device#show ipv6 raguard whitelist all
whitelist #1 : 3 entries
        permit fe80:db8::db8:10/128
        permit fe80:db8::db8:5/128
        permit fe80:db8::db8:12/128

To verify the RA guard configuration for a specific VLAN, enter the show ipv6 raguard vlan command followed by the ID of VLAN you want to check.

The following example displays output for a VLAN in a non-SPX environment.

device# show ipv6 raguard vlan 320
VLAN     Policy
-----    ------
320      policy650
device#

The following example shows that RA guard policy20 is applied on VLAN 2001. The last line indicates that the VLAN contains CB SPX cascade ports to which the RA guard policy has been applied.

device(config-vlan-2001)# show ipv6 raguard vlan 2001
VLAN     Policy
-----    ------
2001     policy20
RA guard Cascade-port rule created for ports: 1/1/1 2/1/15 2/1/20 3/1/20