Configuring Neighbor Discovery Inspection on Multiple VLANs

Neighbor discovery (ND) inspection can be enabled on multiple VLANs using one command. The following task configures multiple VLANs and enables ND inspection on most of the configured VLANs using one command.
  1. Enter global configuration mode.
    device# configure terminal
  2. Configure the port-based VLANs.
    device(config)# vlan 100 to 150
  3. Add port Ethernet 1/1/12 as a tagged port.
    device(config-mvlan-100-150)# tagged ethernet 1/1/12
  4. Use the exit command to return to global configuration mode.
    device(config-mvlan-100-150)# exit
  5. Configure more port-based VLANs.
    device(config)# vlan 151 to 200
  6. Add port Ethernet 1/1/12 as a tagged port.
    device(config-mvlan-151-200)# tagged ethernet 1/1/12
  7. Use the exit command to return to global configuration mode.
    device(config-mvlan-151-200)# exit
  8. Use the ipv6 neighbor inspection vlan command with the to keyword, specifying a VLAN range, to enable ND inspection on multiple VLANs.
    device(config)# ipv6 neighbor inspection vlan 100 to 150 160 170 to 200
    The command enables ND inspection on VLANs 100 through 150, VLAN 160, and VLANs 170 through 200.
  9. Use the ipv6 neighbor inspection command to add a static ND inspection entry. You can add multiple static ND inspection entries.
    device(config)# ipv6 neighbor inspection 2001::1 0000.1234.5678
  10. Use the interface ethernet command to enter the interface configuration mode.
    device(config)# interface ethernet 1/1/1
  11. Use the ipv6-neighbor inspection trust command to enable trust mode for the switch or server port. You can enable trust mode for multiple ports.
    device(config-if-e1000-1/1/1)# ipv6-neighbor inspection trust

The following example configures multiple VLANs and enables ND inspection on VLANS 100 through 150, VLAN 160, and VLANs 170 through 200. It also designates port 1/1/1 as trusted.

device# configure terminal
device(config)# vlan 100 to 150
device(config-mvlan-100-150)# tagged ethernet 1/1/12
device(config-mvlan-100-150)# exit
device(config)# vlan 151 to 200
device(config-mvlan-151-200)# tagged ethernet 1/1/12
device(config-mvlan-100-150)# exit
device(config)# ipv6 neighbor inspection vlan 100 to 150 160 170 to 200
device(config)# ipv6 neighbor inspection 2001::1 0000.1234.5678
device(config)# interface ethernet 1/1/1
device(config-if-e1000-1/1/1)# ipv6-neighbor inspection trust