raguard

Configures the current interface as a trusted, untrusted, or host Router Advertisement (RA) guard port.
Syntax
raguard { trust | untrust | host }
no raguard { trust | untrust | host }
Parameters
trust
Configures an interface as a trusted RA guard port.
untrust
Configures an interface as an untrusted RA guard port.
host
Configures an interface as a host RA guard port.
Modes

Interface configuration mode

Usage Guidelines

The no form of this command removes the current trusted or untrusted configuration.

A trusted RA guard port forwards all the receive RA packets without inspecting. An untrusted port inspects the received RAs against the RA guard policy’s whitelist, prefix list and preference maximum settings before forwarding the RA packets. If an RA guard policy is not configured on an untrusted or host port, all the RA packets are forwarded.

Examples

The following example configures an interface as a trusted RA guard port:

device(config)# interface ethernet1/1/1
device(config-int-e1000-1/1/1)# raguard trust

The following example configures an interface as an untrusted RA guard port:

device(config)# interface ethernet1/2/1
device(config-int-e1000-1/2/1)# raguard untrust

The following example configures an interface as a host RA guard port:

device(config)# interface ethernet3/2/1
device(config-int-e1000-3/2/1)# raguard host