29
661
-
stateless—IPv6 addresses are bound from NDP messages, and only
global addresses belonging to learned prefixes with set A-flag or
prefixes manually configured with the autoconfig keyword are allowed.
-
any—IPv6 addresses are bound from NDP messages and only global
addresses belonging to prefixes in NPT are allowed.
Use the dhcp keyword, to allow binding from DHCPv6 message. IPv6 addresses
bound from DHCPv6 messages are never verified against the Neighbor Prefix
table. IPv6 addresses bound from DHCPv6 messages override IPv6 addresses
bound from NDP messages.
Note. If the dhcp keyword is not configured, the switch will bind IPv6 addresses
assigned by DHCPv6 from NDP messages, because a host must execute the DAD
process for these addresses.
If no keyword is defined the ipv6 neighbor binding address-config any command
is applied.
Examples
Example 1. The following example specifies that any global IPv6 address
configuration method can be applied and there will be no binding from DHCPv6
messages:
switchxxxxxx(config)#
switchxxxxxx(config)#
Example 2. The following example specifies that any global IPv6 address binding
from NDP and global IPv6 address binding from DHCPv6 messages can be
applied:
switchxxxxxx(config)#
switchxxxxxx(config)# ipv6 neighbor binding address-config any dhcp
Example 3. The following example specifies that only stateless global IPv6
address binding from NDP can be applied
switchxxxxxx(config)#
ipv6 neighbor binding address-prefix-validation
ipv6 neighbor binding address-config any
ipv6 neighbor binding address-prefix-validation
ipv6 neighbor binding address-prefix-validation
Cisco Sx350 Ph. 2.2.5 Devices - Command Line Interface Reference Guide
IPv6 First Hop Security