Configuration Notes and Feature Limitations for IPv6 Source Guard

The following configuration notes and feature limitations apply to IPv6 Source Guard (IPSGv6):

  • Configuring IPSGv6 static entries at the VLAN or port level is allowed only after IPSGv6 is configured at the VLAN level, at the port level, or both.
  • IPSGv6 configuration can be removed at the VLAN or port level only after all IPSGv6 static entries are unconfigured at the VLAN or port level.
  • IPSGv6 is not supported for the default VLAN.
  • If a LAG is undeployed, IPSGv6 configurations are auto-cleared.
  • IPSGv6 configurations are auto-cleared for a VLAN if it is deleted.
  • IPSGv6 cannot be configured for a range of VLANs.
  • IPSGv6 functions across reload.
  • IPSGv6 configurations are supported for all non-default VLANs.
  • IPSGv6 is not supported for VLAN groups.
  • IPSGv6 is not supported for VE interfaces.
  • When configuring IPSGv6 on a range of ports, the configuration succeeds on all valid ports.
  • IPSGv6 and IPv6 ACLs are not supported for the same port.
  • IPSGv6 and Ingress IPv6 ACL are supported together on the same device, as long as they are not configured on the same port or VLAN.
  • IPSGv6 can be enabled on tagged or untagged ports in a VLAN but cannot be configured globally for a VLAN.
  • IPSGv6 can be configured on a maximum of 511 VLANs.
  • IPSGv6 and IPSGv6 ACLs are supported together on the same ICX 8100 or ICX 8200 device only, provided that they are not configured on the same port or VLAN. If IPSGv6 is enabled for a port, VLAN, or interface level, ACLs cannot be applied to inbound traffic on the port for the VLAN or interface using the ipv6 access-group command. When IPSGv6 is configured for a port at the VLAN or interface level, an error will occur if you attempt to apply an ACL to inbound traffic. To bind an IPSGv6 ACL to an interface for incoming traffic, use the ipv6 sg-access-group command. Refer to the ipv6 sg-access-group command in the RUCKUS FastIron Command Reference for more information.
  • The recommended number of entries for RUCKUS ICX devices is outlined in the following table:

    Recommended Number of Entries for RUCKUS ICX Devices

    Devices Recommended Maximum Number of IPSGv6 Entries Per Device
    RUCKUS ICX 7550 2048
    RUCKUS ICX 7650 2048
    RUCKUS ICX 7850 1536
    RUCKUS ICX 8100 512
    RUCKUS ICX 8200 512

    The recommended maximum number of IPSGv6 entries on a stack of RUCKUS ICX 7550, ICX 7650, ICX 7850, or ICX 8200 devices is 8192.

  • You can enable IPSGv6 on a range of ports within a given slot only, for example, ports 1/1/1 thru 1/1/24. Enabling IPSGv6 across multiple slots is not supported.
  • If you enable IPSGv6 in a network topology that has DHCPv6 clients, you must also enable DHCPv6 snooping. If you do not enable DHCPv6 snooping, all IPv6 traffic, including DHCPv6 packets, is blocked.
  • Rate-limiting based on source IPv6 address cannot be combined with IPSGv6. Thus, a fixed rate-limit input cannot be configured when IPSGv6 is enabled on the port.