Trusted, Untrusted, and Host Ports
IPv6 RA guard classifies interfaces on devices as trusted, untrusted, or host ports. For the trusted, untrusted, or host port configuration to take effect, the RA guard policy must be applied to the VLAN the ports are a part of.
By default, all interfaces are configured as host ports. On a host port, all the RAs are dropped with a policy configured on the VLAN.
Trusted ports are those that receive RAs within the network. Trusted ports allow received RAs to pass through without checking.
Depending on the configured policy settings, an RA packet is either forwarded through the interface or dropped. If you do not configure an RA guard policy on an untrusted or host port, all RAs are forwarded.