255
interface interface-type interface-
number
Configure dynamic IPv6 source
guard binding function
ip check source ipv6 { ip-address
| ip-address mac-address | mac-
address }
Required
Not configured by default
NOTE:
ï‚· To implement dynamic IPv6 source guard binding, make sure that DHCPv6 snooping or ND snooping is
configured and works normally. For DHCPv6 and ND snooping configuration information, see the
Layer 3—IP
Services Configuration Guide
.
ï‚· If you configure dynamic IPv6 source guard binding on a port for multiple times, the last configuration will
overwrite the previous configuration on the port.
ï‚· If you configure both ND snooping and DHCPv6 snooping on the device, IP source guard generates IP source
guard entries based on the DHCPv6 snooping entries, which are usually generated first, to filter packets on a
port.
Displaying and maintaining IP source guard
For IPv4:
Display static IP source guard
binding entries
display user-bind [ interface interface-type
interface-number | ip-address ip-address |
mac-address mac-address ] [ slot slot-
number ] [ | { begin | exclude | include }
regular-expression ]
Display dynamic IP source guard
binding entries
display ip check source [ interface
interface-type interface-number | ip-
address ip-address | mac-address mac-
address ] [ slot slot-number ] [ | { begin |
exclude | include } regular-expression ]
For IPv6:
Display static IPv6 source guard
binding entries
display user-bind ipv6 [ interface interface-
type interface-number | ip-address ip-
address | mac-address mac-address ] [ slot
slot-number ] [ | { begin | exclude | include
} regular-expression ]
Display dynamic IPv6 source
guard binding entries
display ip check source ipv6 [ interface
interface-type interface-number | ip-address
ip-address | mac-address mac-address ] [
slot slot-number ] [ | { begin | exclude |
include } regular-expression ]