enable nd hop-limit

For an IPv6 ACL, enables dropping neighbor discovery (ND) packets for which the hop limit is less than 255.
Syntax
enable nd hop-limit
no enable nd hop-limit
Command Default

Hop-limit check for neighbor discovery (ND) packets is disabled.

Modes

IPv6 ACL configuration mode

Usage Guidelines

Checking for ND packets with hop limit less than 255 helps protect the device from denial of service (DoS) attacks.

ACLs enabled for hop-limit check are effective only when applied to interfaces. (If you configure an ACL that is already applied to an interface, there is no need to re-apply it.)

This command is effective in ACLs applied to all types of supported interface—physical, port-channel, and VE.

This command applies to the following types of ND packets:

  • neighbor advertisement (NA)
  • neighbor solicitation (NS)
  • router advertisement (RA)
  • router solicitation (RS)

To disable hop-limit check for ND packets, use the no form of this command.

Examples

The following example enables hop-limit check for the IPv6 ACL being configured.

device# configure terminal
device(config)# ipv6 access-list hl_acl
device(config-ipv6-access-list hl_acl)# enable nd hop-limit

The following example disables hop-limit check for the IPv6 ACL being configured.

device# configure terminal
device(config)# ipv6 access-list hl_acl
device(config-ipv6-access-list hl_acl)# no enable nd hop-limit
History
Release version Command history
08.0.61 This command was introduced.
08.0.30p Support for this command for ICX 7xxx devices was added.