IPv6 First Hop Security
Cisco Sx350 Ph. 2.2.5 Devices - Command Line Interface Reference Guide
Example
The following example enables the switch to specify 2 as the minimum CGA
security level:
switchxxxxxx(config)#
29.29 ipv6 nd inspection validate source-mac
To globally enable checking source MAC address against the link-layer address in
the source/target link-layer option, use the ipv6 nd inspection validate source-mac
command in Global Configuration mode. To disable this function, use the no form
of this command.
Syntax
ipv6 nd inspection validate source-mac
no ipv6 nd inspection validate source-mac
Parameters
N/A
Default Configuration
This command is disabled by default.
Command Mode
Global Configuration mode
User Guidelines
When the switch receives an NDP message, which contains a link-layer address in
the source/target link layer option, the source MAC address is checked against
the link-layer address. Use this command to drop the packet if the link-layer
address and the MAC addresses are different from each other.
ipv6 nd inspection sec-level minimum 2
29
646