Enabling IPv6 Source Guard for a VLAN

You can enable IPv6 Source Guard (IPSGv6) on a switch or a router for a range of ports in a VLAN or on the entire VLAN.
  1. Enter global configuration mode.
    device# configure terminal
  2. Configure the port-based VLAN.
    device(config)# vlan 12
  3. Add ports Ethernet 1/1/5 through 1/1/8 as untagged ports.
    device(config-vlan-12)# untagged ethernet 1/1/5 to 1/1/8
  4. Add ports Ethernet 1/1/23 through Ethernet 1/1/24 as tagged ports.
    device(config-vlan-12)# tagged ethernet 1/1/23 to 1/1/24
    
  5. Enable IPSGv6 on the tagged ports.
    device(config-vlan-12)# ipv6 source-guard enable ethernet 1/1/23 to 1/1/24

The following example configures IPSGv6 on a VLAN.

device# configure terminal
device(config)# vlan 12
device(config-vlan-12)# untagged ethernet 1/1/5 to 1/1/8
device(config-vlan-12)# tagged ethernet 1/1/23 to 1/1/24
device(config-vlan-12)# ipv6 source-guard enable ethernet 1/1/23 to 1/1/24

The following example configures IPSGv6 on a single port on a VLAN.

device# configure terminal
device(config)# vlan 12
device(config-vlan-12)# untagged ethernet 1/1/5 to 1/1/8
device(config-vlan-12)# tagged ethernet 1/1/23 to 1/1/24
device(config-vlan-12)# ipv6 source-guard enable ethernet 1/1/23

The following example configures IPSGv6 on all ports on a VLAN.

device# configure terminal
device(config)# vlan 12
device(config-vlan-12)# untagged ethernet 1/1/5 to 1/1/8
device(config-vlan-12)# tagged ethernet 1/1/23 to 1/1/24
device(config-vlan-12)# ipv6 source-guard enable

The following example configures IPSGv6 on a LAG interface on a VLAN.

device# configure terminal
device(config)# vlan 12
device(config-vlan-12)# untagged ethernet 1/1/5 to 1/1/8
device(config-vlan-12)# tagged ethernet 1/1/23 to 1/1/24
device(config-vlan-12)# ipv6 source-guard enable lag 1