3 ipv6 security ra typical examples, 4 ipv6 security ra troubleshooting help, Ecurity – QTECH QSW-3400 Инструкция по настройке User Manual

Page 367: Ypical, Xamples, Roubleshooting

background image

+7(495) 797-3311 www.qtech.ru
Москва, Новозаводская ул., 18, стр. 1

366

debug ipv6 security-ra

no debug ipv6 security-ra

Enable the debug information of IPv6 security

RA module, the no operation of this command

will disable the output of debug information of

IPv6 security RA.

show ipv6 security-ra [interface

list>]

Display the distrust port and whether globally

security RA is enabled.

47.3 IPv6 Security RA Typical Examples

IPv6 Security RA sketch map

Instructions: if the illegal user in the graph advertises RA, the normal user will receive the RA,

set the default router as the vicious IPv6 host user and change its own address. This will

cause the normal user to not be able to connect the network. We want to set security RA on

the 1/2 port of the switch, so that the RA from the illegal user will not affect the normal user.

Switch configuration task sequence:
Switch#config
Switch(config)#ipv6 security-ra enable
Switch(Config-If-Ethernet1/2)# ipv6 security-ra enable

47.4 IPv6 Security RA Troubleshooting Help

The function of IPv6 security RA is quite simple, if the function does not meet the expectation

after configuring IPv6 security RA:

Check if the switch is correctly configured.

Illegal User

PC

User

Other IPv6 network

RA

Ethernet1/1

Ethernet1/3

Ethernet1/2

RA

X