Configuration considerations
Configure Switch B as follows:
Enable SAVI.
Enable global unicast address ND snooping and link-local address ND snooping. For more information about ND snooping, see Layer 3—IP Services Configuration Guide.
Enable ND detection in VLAN 10 to check the ND packets arrived on the ports. For more information about ND detection, see "Configuring ND attack defense."
Configure a static IPv6 source guard binding entry on each interface connected to a host. This step is optional. If this step is not performed, SAVI does not check packets against static binding entries. For more information about static IPv6 source guard binding entries, see "Configuring IP source guard."
Configure dynamic IPv6 source guard binding on the interfaces connected to the hosts. For more information about dynamic IPv6 source guard binding, see "Configuring IP source guard."
Enable DHCPv6 snooping and leave the interface connected to the gateway as its default status (non-trusted port) so that the hosts cannot obtain IP addresses through DHCPv6. For more information about DHCPv6 snooping, see Layer 3—IP Services Configuration Guide.