IPv6 First Hop Security
OL-32830-01 Command Line Interface Reference Guide
25.27 ipv6 nd inspection policy
To define an ND Inspection policy and place the switch in IPv6 ND Inspection
Policy Configuration mode, use the ipv6 nd inspection policy command in Global
Configuration mode. To remove the ND Inspection policy, use the no form of this
command.
Syntax
ipv6 nd inspection policy
no ipv6 nd inspection policy
Parameters
•
policy-name
—The ND Inspection policy name (up to 32 characters).
Default Configuration
No ND Inspection policies are configured.
Command Mode
Global Configuration mode
User Guidelines
This command defines the ND Inspection policy name, and places the router in ND
Inspection Policy Configuration mode.
The following commands can be configured into a ND Inspection policy:
•
device-role (ND Inspection Policy)
•
drop-unsecure
•
sec-level minimum
•
validate source-mac
Each policy of the same type (for example, ND Inspection policies) must have a
unique name. Policies of different types can have a same policy name.
The switch supports two predefined ND Inspection policies named: "vlan_default"
and "port_default":
ipv6 nd inspection policy vlan_default
exit
policy-name
policy-name
25
520