Global Static Ip Source Guard Configuration - HP 10500 Series Configuration Manual

Security configuration guide
Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

Figure 96 Network diagram
Configuration procedure
# Enable the IPv6 source guard function on GigabitEthernet 1/0/1.
<Device> system-view
[Device] interface gigabitethernet 1/0/1
[Device-GigabitEthernet1/0/1] ipv6 verify source ipv6-address mac-address
# Configure GigabitEthernet 1/0/1 to allow only IPv6 packets with the source MAC address of
0001-0202-0202 and the source IPv6 address of 2001::1 to pass.
[Device-GigabitEthernet1/0/1] ipv6 source binding ipv6-address 2001::1 mac-address
0001-0202-0202
[Device-GigabitEthernet1/0/1] quit
Verifying the configuration
# On the device, display information about static IPv6 source guard entries. The output shows that the
binding entry is configured successfully.
[Device] display ipv6 source binding static
Total entries found: 1
MAC Address
0001-0202-0202

Global static IP source guard configuration

Network requirements
Device A is a distribution layer device. Device B is an access device. Host A in VLAN 10 and Host B in
VLAN 20 communicate with each other through Device A.
Configure Device B to discard attack packets that exploit the IP address or MAC address of Host A and
Host B.
Configure Device B to forward packets of Host A and Host B normally.
IP Address
VLAN
2001::1
N/A
248
Interface
GE1/0/1
Type
Static-IPv6

Advertisement

Table of Contents
loading

Table of Contents