Configuration Notes and Feature Limitations for IPv6 RA Guard
- If an IPv6 ACL matching an ICMPv6 type RA packet is configured on an interface that is part of an RA guard-enabled VLAN, RA guard policy configuration takes precedence.
- IPv6 RA guard does not offer protection in environments where IPv6 traffic is tunneled.
- IPV6 RA guard can be configured on a switch port interface in the ingress direction and is supported only in the ingress direction; it is not supported in the egress direction.
- On ICX 7450 and ICX 7550 devices running a switch image, CPU utilization is high (approximately 99%) while RA guard traffic is sent at a rate of 1,000 packets per second or higher.