You must enable javascript in order to view this page or you can go
here
to view the webhelp.
Contents
Search
Loading, please wait ...
Aruba 3810 / 5400R IPv6 Configuration Guide for ArubaOS-Switch 16.06
Home
About this guide
Applicable products
Switch prompts used in this guide
IPv6 addressing configuration
Configuring IPv6
Commands for configuring IPv6 address
ipv6 enable
Commands to view currently configured IPv6 unicast addresses
Enable auto configuration of a global unicast address and a default router identity on a VLAN
ipv6 address autoconfig
Commands to view current IPv6 autoconfiguration settings
Default IPv6 gateway
ipv6 address dhcp full
Configuring a static IPv6 address on a VLAN
ipv6 address link-local
Commands to statically configure a global unicast address
Operating notes
Duplicate address detection (DAD) for statically configured addresses
IPv6 loopback interfaces
interface loopback
show ipv6
Commands to view the current IPv6 addressing configuration
show ipv6 nd
show ipv6 vlan
show run
View IPv6 gateway, route, and router neighbors
show ipv6 route
show ipv6 routers
Address lifetimes
Preferred lifetime
Valid lifetime
DHCPv6 client
ipv6 dhcp-client
Duplicate address detection (DAD) for statically configured addresses
IPv6 loopback interfaces
Commands to disable IPv6 on a VLAN
Neighbor Discovery (ND)
Duplicate address detection (DAD)
DAD operation
Configuring DAD
ipv6 nd reachable-time
Operating notes for ND
Router access and default router selection
Router advertisements
IPv6 router advertisement options for DNS configuration
nd suppress-ra-dns
IP interface configuration
Display configuration
Router solicitations
Default IPv6 router
Router redirection
IPv6 management features
Viewing the neighbor cache
show ipv6 neighbors
clear ipv6 neighbors
IPv6 Telnet operations
Using outbound Telnet to another device
telnet link-local-addr
telnet global-unicast-addr
show telnet
telnet-server listen
show console
sntp server priority
show sntp
show timep
ip timep
TFTP files transfer over IPv6
Upload/download files to the switch using TFTP
tftp client|server
Commands to copy files over IPv6 using TFTP
copy tftp target
copy source tftp
auto tftp
SNMP management for IPv6
Supported SNMP features
Supported SNMP configuration commands
snmp-server host
snmpv3 targetaddress
IP preserve for IPv6
ip preserve
Downloading an IP preserve configuration file to an IPv6-based switch
Verifying how IP preserve was implemented in a switch
View the neighbor cache
Clear the neighbor cache
IPv6 management security features
ipv6 authorized-managers
Single station access configuration
Multiple station access configuration
Viewing an authorized IP managers configuration
Commands to authorize manager access
Editing an existing authorized IP manager entry
Deleting an authorized IP manager entry
SSH for IPv6
ip ssh
show ip ssh
ip ssh filetransfer
Authorized IP managers for IPv6
Features of authorized IP managers
ipv6 mask
About configuring multiple station access
SCP and SFTP for IPv6
ip ssh filetransfer
Multicast Listener Discovery snooping
Multicast addressing
Multicast Listener Discovery(MLD)
MLD snooping
MLD operation
Forwarding in MLD snooping
ipv6 mld
ipv6 mld version
ipv6 mld port
Queries
ipv6 mld querier
ipv6 mld query-interval
ipv6 mld query-max-response-time
ipv6 mld robustness
ipv6 mld last-member-query-interval
ipv6 mld fastlearn
Leaves
Fast leaves and forced fast leaves
ipv6 mld fastleave
ipv6 mld forcedfastleave
Current MLD status
show ipv6 mld
show ipv6 mld link-local
show ipv6 mld vlan link-local
Current MLD configuration
show ipv6 mld config
Commands to list currently joined ports
show ipv6 mld statistics
Counters
show ipv6 mld vlan counters
mld reload
ipv6 mld send-router-alert
Listeners and joins
Access Control Lists
Overview of Access Control List
Types of IPv6 ACLs
Concurrent IPv4 and IPv6 ACLs
Multiple ACL assignments on an interface
About filtering inbound traffic with multiple ACLS
Filtering outbound traffic
Permitting traffic filtered through multiple ACLs
Features common to all ACL applications
IPv6 ACLs
Create, enter and configure an ACL
IPv6 ACL applications
RACL applications
VACL applications
IPv6 static port ACL applications
RADIUS-assigned (dynamic) port ACL applications
Operating notes for IPv6 applications
General ACL operations
Deleting an ACL in the Running Configuration
Procedures for planning and configuring ACLs
IPv6 ACL operation
Packet filtering process
Packet-filtering
Planning an ACL application
IPv6 traffic management and improved network performance
Security
Guidelines for planning the structure of an ACL
ACL configuration considerations
How an ACE uses a prefix to screen packets for SA and DA matches
Prefix usage differences between ACLs and other IPv6 addressing
Configuring and assigning an IPv6 ACL
Implementing IPv6 ACLs
Permit/deny options
Implicit deny override
ACL configuration
ACL Configuration Structure
ACL configuration considerations
The sequence of entries in an ACL is significant
Implied deny function
Assignment of an ACL to an interface
Assignment of an ACL name to an interface
Creating an ACL using the CLI
General ACE rules
Adding or inserting an ACE in an ACL
Deleting an ACE
Duplicate ACE sequence numbers
ipv6 access-list ascii-str
Commands to configure ACEs in an ACL
[deny|permit]ipv6
[any|hostSA|SA/prefix-length]
[any|host DA|DA/prefix-length]
[ dscp codepoint/precedence ]
ACL Bypass
ipv6 access-list deny-non-classifiable-layer4-header
show running-config
show statistics aclv6
show access list
show access-list config
clear statistics
show access-list resources
TCP and UDP traffic configuration in IPv6 ACLs
Commands to configure TCP
Commands to configure UDP
comparison-operator tcp/udp-src-port
Port number or well-known port name
Comparison operators and well-known port names
Filtering ICMP traffic
Commands to filter ICMP traffic
vlan ipv6 access-group identifier
Filtering routed or switched IPv6 traffic inbound on a VLAN
Filtering inbound IPv6 traffic per port and trunk
Deleting an ACL
[permit|deny] ipv6 -ACE-criteria
Deleting an ACE from an existing ACL
ipv6 access-list resequence
Remarks
remark remark-str
Appending remarks and related ACEs to the end of an ACL
Inserting remarks and related ACEs within an existing list
Inserting a remark for an ACE that exists in an ACL
Replacing an existing remark
Removing a remark from an existing ACE
Operating notes for remarks
Displaying ACL data
show access-list
show access-list config
show access-list vlan
show access-list tunnel
show access-list ports
show access-list identifier
Descriptions of data types included in show access-list command output
Options for applying IPv6 ACLs on the switch
Static ACLS
RADIUS-assigned ACLs
Static ACL performance monitoring
Commands for monitoring static ACL performance
[show|clear] statistics
ACE counter operation
About resetting ACE hit counters to zero
Editing ACLs
General editing rules
Sequence numbering in ACLs
Appending a new ACE to the end of an ACL
Appending an ACE to an existing list
About viewing all ACLs and their assignments in the switch startup-config file and running-config file
Creating or editing an ACL offline
The offline process
Testing and troubleshooting ACLs
Enable IPv6 ACL "Deny" or “Permit” logging
Enabling ACL logging on the switch
Commands for applying an ACL with logging
CIDR notation usage to enter the IPv6 ACL prefix length
IPv6 ACL configuration in a routed environment
IPv6 counter operation with multiple interface assignments
IPv4 counter operation with multiple interface assignments
IPv6 routing basics
IPv6 routing overview
Dual stack IPv4/IPv6 operation
show ip ospf
no ip router id
Changing an existing router ID
Commands to view manually configured router ID
ipv6 hop-limit
ipv6-gateway-addr
show ipv6 route
Enabling IPv6 routing
Configuring a router ID
IPv6 networks and subnets
VLANs and routing
Link-local
Global unicast
IPv6 management interface
IPv6 routing operation
Concurrent static and dynamic routing operation
Router Advertisements (RAs)
Commands to enable IPv6 routing automatically
DHCPv6-relay
Global IPv6 routing parameters configuration
System router ID
Automatic router ID selection
Different route types in the IPv6 routing table
Routing table content
Destination network
Gateway for forwarding routed traffic
Metric and administrative distance
IPv6 static routing
ipv6 route dest
show ipv6 route
Static routing overview
Advantages of static routing
Disadvantages of static routing
Static route types
Static routing default settings
Static route states follow VLAN states
Static routes for ECMP applications
BFD static routing
IPv6 router advertisements
Global configuration context commands
ipv6 nd suppress-ra
ipv6 unicast-routing
VLAN or tunnel context ND configuration
ipv6 nd ra managed-config-flag
ipv6 nd ra other-config-flag
Commands to configure the range for intervals between RA transmissions on a VLAN
ipv6 nd ra max-interval
ipv6 nd ra min-interval
ipv6 nd ra hop-limit
ipv6 nd ra lifetime
ipv6 nd ra reachable-time
ipv6 nd ra ns-interval
Commands to configure global unicast prefix and lifetime for hosts on a VLAN
ipv6 nd ra prefix
valid-lifetime preferred-lifetime
no-autoconfig
off-link
ipv6 nd ra suppress
IPv6 Router Advertisements restrictions
ipv6 ra-guard ports
Router advertisement operations
show ipv6 nd ra
Router advertisement general operation
Setting IPv6 router advertisement policies
Configuring IPv6 router advertisement
About configuring router advertisements on multiple switches with a common VLAN
DHCPv6–Relay
Commands to enable and configure DHCPv6–relay
dhcpv6–relay
ipv6 helper-address
show ipv6 helper-address
show run for DHCPv6
DHCPv6-relay multicast operations
About configuring DHCPv6–Relay
DHCPv6–relay request forwarding
DHCPv6-relay helper addresses
Enabling DHCPv6–relay operation
Multiple-hop forwarding of DHCPv6 service requests
OSPFv3 routing
Overview of OSPFv3
Hello packets
Link-state advertisements (LSAs)
area <AREA-ID> security
area <AREA-ID> security disable
ipv6 ospf3 security
ipv6 ospf3 security disable
show ipv6 ospf3 security
show ipv6 ospfv3 ipsec summary
show crypto ipsec
OSPFv3 area types
Normal area
Backbone area
Stub area
Not-so-stubby-area (NSSA)
OSPFv3 router types
Interior routers
Area border routers (ABRs)
Configuring an ABR to use a virtual link to the backbone
Configuring ranges on an ABR to reduce advertising to the backbone
Autonomous system boundary router (ASBR)
Designated routers
OSPFv3 activation and dynamic configuration
Configuration procedures for OSPFv3
Configuration rules
OSPFv3 global and interface settings
Configuring a virtual link
area virtual-link router-id
Adjusting a dead interval on a virtual link
area virtual-link dead-interval
adjust hello interval
adjust retransmit interval
adjust transit delay
ipv6 ospf3 passive
show ipv6 ospf3 virtual-link
show ipv6 ospf3 virtual-neighbor
OSPFv3 passive
router ospf3 redistribute
Command to modify the default metric for redistribution
Command to modify the redistribution metric type
Reducing AS-external-LSAs and inter-area-prefix-LSAs
Algorithm for AS-external-LSA reduction
About replacing inter-area-prefix-LSAs and type-7-external-LSA default routes with an AS-external-LSA default route
Enforcing strict LSA operation for graceful restart helper mode
route-map name
router ospf3 trap
Troubleshooting: Logging neighbor adjacency change events
logging neighbor-adjacency
Commands to activate OSPFv3
Commands to configure OSPFv3 on the routing switch
ip router-id
ipv6 unicast-routing
router ospf3 [enable|disable]
About assigning the routing switch to OSPFv3 areas
area [ospf3–area-id|backbone][ normal ]
area ospf3–area-id stub/area ospf3–area id nssa
Command to enable OSPFv3 on an interface and assigning one or more VLANs to each area
vlan vid ipv6 ospf3
Command to assign IPv6 loopback addresses to an area
interface loopback
route-map name
router ospf3 redistribute
Command to modify the default metric for redistribution
Command to modify the redistribution metric type
Redistributing/Assigning Loopback IPv6 address to OSPFv3
Verifying the OSPFv3 redistribution of loopback interfaces
OSPFv3 redistribution of loopback addresses
Configuring for external route redistribution in an OSPFv3 domain
Influencing route choices by changing the administrative distance default
distance [external|inter-area|intra-area]
restart strict-lsa
Enforcing strict LSA operation for graceful restart helper mode
Adjusting performance by changing the VLAN interface settings
ipv6 ospf3 cost
ipv6 ospf3 dead-interval
ipv6 ospf3 hello-interval
ipv6 ospf3 priority
ipv6 ospf3 retransmit-interval
ipv6 ospf3 transit-delay
Viewing a summary of OSPFv3 configuration information
show ipv6 route ospf3
show ipv6 ospf3 area
show ipv6 ospf3 interface
show ipv6 ospf3 neighbor
show/clear ipv6 ospf3 statistics
show ipv6 ospf3 link-state as-scope
ospf3 link-state area-scope
show ospf3 link-state link-scope information
show ipv6 ospf3 redistribute
show ipv6 ospf3 virtual-link
show ipv6 ospf3 virtual-neighbor
show ipv6 ospf3 spf-log
show running
router ospf3 trap
debug ipv6 ospf3
Graceful shutdown of OSPFv3 Routing
Modules operating in non-stop mode
ip load-sharing
Equal-cost multi-path routing
Influencing route choices by changing the default administrative distance
Adjusting performance by changing the VLAN interface settings
PIMv6
Configuring PIMv6
router pim6
enable|disable
join-prune-interval
rp-address
rpf-override
spt-threshold
state-refresh
trap
bsr-candidate
bsr-candidate bsm-interval
bsr-candidate hash-mask-length
bsr-candidate priority
bsr-candidate source-ip-vlan
rp-candidate
rp-candidate hold-time
rp-candidate priority
rp-candidate group-prefix
rp-candidate source-ip-vlan
Configuring PIMv6 DM
ipv6 pim6-dense
graft-retry-interval
hello-delay
hello-interval
lan-prune-delay
max-graft-retries
override-interval
propagation-delay
Configuring PIMv6 SM
ipv6 pim6-sparse
dr-priority
hello-delay
hello-interval
lan-prune-delay
override-interval
propagation-delay
Viewing PIMv6 information
show ipv6
show ipv6 pim6
show ipv6 pim6 pending
show ipv6 pim6 bsr
show ipv6 pim6 bsr local
show ipv6 pim6 bsr elected
show ipv6 pim6 rp-set
show ipv6 pim6 rp-candidate
show ipv6 pim6 rp-candidate config
show ipv6 pim6 rpf-override
show ipv6 pim6 rpf-override source
show ipv6 pim6 interface
show ipv6 pim6 neighbor
show ipv6 pim6 mroute
IPv6 tunneling over IPv4 using manually configured tunnels
Commands to configure a tunnel interface
interface tunnel
tunnel [enable|disable]
tunnel name string
tunnel mode
tunnel source
tunnel destination
tunnel mtu
tunnel tos
tunnel ttl
Manual 6in4 tunneling
Configuring switch B for manual 6in4 tunneling
Configuring switch C for 6in4 tunneling
Example: Tunneling using Policy-Based Routing (PBR)
Configuring switch B for PBR-based routing
Configuring switch C for PBR-based routing
Viewing tunnel configuration and status
Show interface tunnel brief
show ipv6 nd ra prefix tunnel
Show IP counters for a tunnel
Service insertion
IPv6 diagnostic and troubleshooting
ICMP rate-limiting
ipv6 icmp error-interval
Ping for IPv6 (Ping6)
ping6 ipv6–address
Traceroute for IPv6
traceroute6
DNS resolver for IPv6
DNS configuration
ip dns server-address priority
ip dns domain-name
Commands to view the current DNS configuration
Debug/Syslog for IPv6
Configuring debug and event log messaging
debug ipv6
debug destination
logging syslog-ipv4–address
show debug
IPv6 network defense ND snooping and detection
Overview of IPv6 network defense ND snooping and detection
ICMPv6 messages
ND attacks
Commands
ipv6 nd mac-check
ipv6 nd snooping
ipv6 nd snooping vlan
clear ipv6 nd snooping bindings ipv6-address
ipv6 nd snooping prefix-list
About configuring maximum learn entries on a port
ipv6 nd snooping max-binding
ipv6 nd snooping trust ethernet
clear ipv6 nd snooping statistics
snmp-server enable traps nd-snooping
debug ipv6 nd
Show commands
show ipv6 nd snooping
show ipv6 nd snooping bindings
show ipv6 nd snooping statistics
show snmp-server traps
Change to existing command: show qos resources
Debug messages for ND snooping
Websites
Support and other resources
Accessing Hewlett Packard Enterprise Support
Accessing updates
Customer self repair
Remote support
Warranty information
Regulatory information
Documentation feedback
Your browser does not support iframes.