Configuration Notes and Feature Limitations for IPv6 Source Guard
The following configuration notes and feature limitations apply to IPv6 Source Guard (IPSGv6):
- Configuring IPSGv6 static entries at the VLAN or port level is allowed only after IPSGv6 is configured at the VLAN level, at the port level, or both.
- IPSGv6 configuration can be removed at the VLAN or port level only after all IPSGv6 static entries are unconfigured at the VLAN or port level.
- IPSGv6 is not supported for the default VLAN.
- If a LAG is undeployed, IPSGv6 configurations are auto-cleared.
- IPSGv6 configurations are auto-cleared for a VLAN if it is deleted.
- IPSGv6 can not be configured for a range of VLANs.
- IPSGv6 functions across reload.
- IPSGv6 configurations are supported for all non-default VLANs.
- RUCKUS ICX devices do not support IPSGv6 and dynamic ACLs on the same port.
- IPSGv6 is not supported for VLAN groups.
- IPSGv6 is not supported for VE interfaces.
- When configuring IPSGv6 on a range of ports, the configuration succeeds on all valid ports.
- IPSGv6 and IPv6 ACLs are not supported for the same port.
- IPSGv6 and Ingress IPv6 ACL are supported together on the same device, as long as they are not configured on the same port or VLAN.
- IPSGv6 can be enabled on tagged or untagged ports in a VLAN but cannot be configured globally for a VLAN.
- IPSGv6 can be configured on a maximum of 511 VLANs.
- The recommended number of entries for RUCKUS ICX
devices is outlined in the following table:
Recommneded Number of Entries for RUCKUS ICX Devices
Devices Recommended Maximum Number of IPSGv6 Entries Per Device RUCKUS ICX 7150 256 RUCKUS ICX 7250 1536 RUCKUS ICX 7450 1408 RUCKUS ICX 7550 2048 RUCKUS ICX 7650 2048 RUCKUS ICX 7850 1536 The recommended maximum number of IPSGv6 entries on a stack of RUCKUS ICX 7250, ICX 7450, ICX 7550, ICX 7650, or ICX 7850 devices is 8192.
- You can enable IPSGv6 on a range of ports within a given slot only, for example, ports 1/1/1 thru 1/1/24. Enabling IPSGv6 across multiple slots is not supported.
- If you enable IPSGv6 in a network topology that has DHCPv6 clients, you must also enable DHCPv6 snooping. If you do not enable DHCPv6 snooping, all IPv6 traffic, including DHCPv6 packets, is blocked.
- IPSGv6 supports multi-VRF instances.
- Rate-limiting based on source IPv6 address cannot be combined with IPSGv6. Thus, a fixed rate-limit input cannot be configured when IPSGv6 is enabled on the port.