IPv6 First Hop Security
Cisco Sx350 Ph. 2.2.5 Devices - Command Line Interface Reference Guide
no ipv6 dhcp guard
Parameters
N/A
Default Configuration
DHCPv6 Guard on a VLAN is disabled.
Command Mode
Interface (VLAN) Configuration mode
User Guidelines
DHCPv6 Guard blocks messages sent by DHCPv6 servers/relays to clients
received on ports that are not configured as a DHCPv6 server. Client messages or
messages sent by relay agents from clients to servers are not blocked. See the
device-role (IPv6 DHCP Guard)
DHCPv6 Guard validates received DHCPv6 messages based on a DHCPv6 Guard
policy attached to the source port.
Examples
Example 1—The following example enables DHCPv6 Guard on VLAN 100:
switchxxxxxx(config)# interface vlan 100
switchxxxxxx(config-if)# ipv6 dhcp guard
switchxxxxxx(config-if)# exit
Example 2—The following example enables DHCPv6 Guard on VLANs 100-107:
switchxxxxxx(config)# interface range vlan 100-107
switchxxxxxx(config-if-range)# ipv6 dhcp guard
switchxxxxxx(config-if-range)# exit
command for details.
29
622