Commands For Ipv6 Security Ra

9.9 Commands for IPv6 Security RA

9.9.1 ipv6 security-ra enable

Command: ipv6 security-ra enable
no ipv6 security-ra enable
Function: Globally enable IPv6 security RA. The RA advertisement messages will not be forwarded through hardware but only sent to the CPU for processing. The no command will globally disable the IPv6 security RA function.
Parameters: None.
Command mode: Global Configuration Mode
Default: Disabled.
Usage guide: After enabling the global security RA function, the security RA on a port can be enabled. Globally disabling security RA will clear all the configured security RA ports. The global security RA function and the global IPv6 SAVI function are mutually exclusive, so they can not be enabled at the same time.
Example: Globally enable IPv6 security RA.

active500EM(config)#ipv6 security-ra enable

 

9.9.2 ipv6 security-ra enable

Command: ipv6 security-ra enable
no ipv6 security-ra enable
Function: Enable IPv6 security RA on a port, causing this port not to forward the received RA message. The no command disables the IPv6 security RA on a port.
Parameters: None.
Command mode: Port Configuration Mode
Default: Disabled.
Usage guide: After globally enabling the security RA function, the security RA on a port is enabled. Globally disabling security RA will clear all the configured security RA ports.
Example: Enable IPv6 security RA on a port.

active500EM(config-if-ethernet1/0/2)#ipv6 security-ra enable

 

9.9.3 show ipv6 security-ra

Command: show ipv6 security-ra [interface <interface-list>] Function: Display all the interfaces with IPv6 RA enabled.
Parameters:

  • <interface-list>: Entering no parameter will display all distrusted ports. Entering a parameter will display the corresponding distrusted port.

Command mode: Admin and Configuration Mode
Default: None.
Usage guide: Display all the interfaces with IPv6 RA enabled.
Example: Display all the interfaces with IPv6 RA enabled.

active500EM#show ipv6 security-ra
IPv6 security RA information:
Global IPv6 Security RA State: Enable
Ethernet1/0/1
IPv6 Security RA State: Yes
Ethernet1/0/3
IPv6 Security RA State: Yes

 

9.9.4 debug ipv6 security-ra

Command: debug ipv6 security-ra
no debug ipv6 security-ra
Function: Enable the IPv6 security RA debug. The no command disables the debug information of IPv6 security RA.
Parameters: None.
Command mode: Admin Mode
Default: None.
Usage guide: Users can check the message handling display of IPv6 security RA.
Example: Enable the IPv6 security RA debug.

active500EM#debug ipv security-ra
ipv6 security ra debug is on

 


Return to Controller Wired CLI Table of Contents