beautypg.com

Configuring port a, Configuring port c, Configuring port b – Brocade FastIron Ethernet Switch Security Configuration Guide User Manual

Page 365

background image

FIGURE 33 IPv6 RA guard configuration in a network

Configuring port A:

Configure port A as a trusted port.

Brocade(config)# interface ethernet 1/1/1

Brocade(config-int-e1000-1/1/1)# raguard trust

Configuring port C:

On port C, create an RA Guard policy with no other options and associate the policy with a VLAN of
which C is a member of. This helps block all RAs from C ports.

Brocade(config)# ipv6 raguard policy policyC

Brocade(ipv6-RAG-policy policyC)# exit

Brocade(config)# ipv6 raguard vlan 1 policyC

Configuring port B:

On port B create an RA Guard policy with supported whitelist. This helps to permit RAs from only those
sources. Associate a whitelist or prefix list with the RA guard policy.

Brocade(config)# ipv6 raguard whitelist 1 permit fe80:db8::db8:10

Brocade(config)# ipv6 raguard whitelist 1 permit fe80:db8::db8:5

Brocade(config)# ipv6 raguard whitelist 1 permit fe80:db8::db8:12

IPv6 RA Guard

FastIron Ethernet Switch Security Configuration Guide

365

53-1003088-03