Trusted, Untrusted, and Host Ports
IPv6 RA guard classifies interfaces on devices as trusted, untrusted, or host ports. For the trusted, untrusted, or host port configuration to take effect, the RA guard policy must be applied to the VLAN the ports are a part of.
By default, all interfaces are configured as host ports. On a host port, all the RAs are dropped with a policy configured on the VLAN.
Trusted ports are those that receive RAs within the network. Trusted ports allow received RAs to pass through without checking.
Depending on the configured policy settings, an RA packet is either forwarded through the interface or dropped. If you do not configure an RA guard policy on an untrusted or host port, all RAs are forwarded.
RA Guard Policies on VLANs in a Campus Fabric Configuration
Untrusted ports trap packets to the CPU and perform RA guard processing. For non-PE units, a trap rule is programmed directly on the unit where the ports are located. However, for PE units in a Campus Fabric (SPX) configuration, an untrust CB cascade rule may be created and configured for all CB SPX cascade ports.
A CB cascade rule is created in the following cases:
- RA guard is enabled on a VLAN with PE 'untrust' ports as members.
- RA guard is enabled on a VLAN with PE ports as members, and logging is enabled in the RA guard policy bound to the VLAN. In this case, the PE member ports can be configured as 'untrust', 'trust', or 'host'.
No CB cascade rule is created when the VLAN has CB ports but no PE ports as members.
When you use the
show ipv6 raguard command to display information on RA guard policies for a VLAN with member ports
that are part of an SPX system, the output indicates whether a CB cascade rule has
been created and, if so, to which SPX cascade ports it applies.
The following example shows that RA guard policy10 is applied to VLAN 1001, but logging is not enabled under the policy. As a result, no cascade-port rule has been created for the cascade ports in this SPX configuration.
device(config-if-pe-e1000-44/1/15)# show ipv6 raguard vlan 1001 VLAN Policy ----- ------ 1001 policy10 RA guard Cascade-port rule not created
The following example indicates an RA guard policy (policy20) with logging enabled is applied on VLAN 2001. The output shows the CB SPX cascade ports where it is applied.
device(config-vlan-2001)# show ipv6 raguard vlan 2001 VLAN Policy ----- ------ 2001 policy20 RA guard Cascade-port rule created for ports: 1/1/1 2/1/15 2/1/20 3/1/20