ipv6 verify source
Syntax
ipv6 verify source { ipv6-address | ipv6-address mac-address | mac-address }
undo ipv6 verify source
View
Layer 2 Ethernet interface view, port group view
Default level
2: System level
Parameters
ipv6-address: Binds source IPv6 addresses to the port.
ipv6-address mac-address: Binds source IPv6 addresses and MAC addresses to the port.
mac-address: Binds source MAC addresses to the port.
Description
Use ipv6 verify source to enable the IPv6 source guard function on a port and specify the elements to be included in the port’s dynamic binding entries.
Use undo ipv6 verify source to restore the default.
By default, the IPv6 source guard function is disabled on a port.
After you configure the IPv6 source guard function on a port, the IPv6 source guard function dynamically generates IPv6 source guard entries based on the DHCPv6 snooping entries or ND snooping entries, and all static IPv6 source guard entries become effective.
You cannot configure the IPv6 source guard function on a port that is in an aggregation group.
Related commands: display ipv6 source binding.
Examples
# Configure dynamic IPv6 binding on Layer 2 Ethernet port Ethernet 1/0/1 to filter IPv6 packets based on the source IPv6 address and MAC address.
<Sysname> system-view [Sysname] interface ethernet 1/0/1 [Sysname-Ethernet1/0/1] ipv6 verify source ipv6-address mac-address