Configuring Neighbor Discovery Inspection on Multiple VLANs
Neighbor discovery (ND) inspection can be enabled on multiple VLANs using one command.
The following task configures multiple VLANs and enables ND inspection on most of
the configured VLANs using one command.
- Enter global configuration mode.
- Configure the port-based VLANs.
- Add port Ethernet 1/1/12 as a tagged port.
- Use the
exitcommand to return to global configuration mode. - Configure more port-based VLANs.
- Add port Ethernet 1/1/12 as a tagged port.
- Use the
exitcommand to return to global configuration mode. - Use the
ipv6 neighbor inspection vlancommand with the to keyword, specifying a VLAN range, to enable ND inspection on multiple VLANs.The command enables ND inspection on VLANs 100 through 150, VLAN 160, and VLANs 170 through 200. - Use the
ipv6 neighbor inspectioncommand to add a static ND inspection entry. You can add multiple static ND inspection entries. - Use the
interface ethernetcommand to enter the interface configuration mode. - Use the
ipv6-neighbor inspection trustcommand to enable trust mode for the switch or server port. You can enable trust mode for multiple ports.
The following example configures multiple VLANs and enables ND inspection on VLANS 100 through 150, VLAN 160, and VLANs 170 through 200. It also designates port 1/1/1 as trusted.
device# configure terminal device(config)# vlan 100 to 150 device(config-mvlan-100-150)# tagged ethernet 1/1/12 device(config-mvlan-100-150)# exit device(config)# vlan 151 to 200 device(config-mvlan-151-200)# tagged ethernet 1/1/12 device(config-mvlan-100-150)# exit device(config)# ipv6 neighbor inspection vlan 100 to 150 160 170 to 200 device(config)# ipv6 neighbor inspection 2001::1 0000.1234.5678 device(config)# interface ethernet 1/1/1 device(config-if-e1000-1/1/1)# ipv6-neighbor inspection trust