beautypg.com

7 ipv6 dhcp snooping binding enable, Dhcp snooping binding enable – PLANET XGS3-24040 User Manual

Page 375

background image


28-88

Function:

After the abnormity is detected by DHCPv6 Snooping, set the max number of blackhole MAC on

each non-trusted port.

Parameters:

max-num: The max number of blackhole MAC that can be sent after DHCPv6 Snooping receives

the response packet of DHCPv6 from non-trusted port, the range from 1 to 200.

default: The limitation number is 10 by default.

Command Mode:

Global mode

Default Settings:

Limit blackhole MAC as 10 by the default port.

Usage Guide:

Set the max number of the blackhole MAC to avoid the resource exhaustion of the switch caused by

attacks. If the number of alarm information is bigger than the setting value, then the earliest

blackhole MAC will be recovered forcibly while the new blackhole MAC take effect.

Example:

After the abnormity is detected by DHCPv6 Snooping, set the max number of blackhole MAC as

100 on each non-trusted port.

switch(config)# ipv6 dhcp snooping action 100

28.7 ipv6 dhcp snooping binding enable

Command:

ipv6 dhcp snooping binding enable

no ipv6 dhcp snooping binding enable

Function:

Enable the DHCPv6 Snooping binding funciton globally. The no command disables the function.

Parameters:

None.

Command Mode:

Globe mode

Default Settings:

DHCPv6 Snooping binding is disabled by default.

Usage Guide:

When enabling the binding function of DHCPv6 Snooping to monitor the DHCPv6 packets, it allows

DHCPv6 Snooping binding to be established. This command limits the dynamic binding and the

static binding. After disable the global DHCPv6 Snooping function, the device stops establishing the

binding according to DHCPv6 packets.

Example:

Establish DHCPv6 Snooping binding according to DHCPv6 REPLY packets.

switch(config)#ipv6 dhcp snooping binding enable