|
Command or Action |
Purpose |
|
enable
Example:
Device> enable
|
Enables privileged EXEC mode.
-
Enter your password if prompted.
|
|
configure terminal
Example:
Device# configure terminal
|
Enters global configuration mode. |
|
ipv6 access-list access-list-name
Example:
Device(config)# ipv6 access-list acl1
|
Defines the IPv6 access list and enters IPv6 access list configuration mode. |
|
permit host address any
Example:
Device(config-ipv6-acl)# permit host FE80::A8BB:CCFF:FE01:F700 any
|
Sets the conditions in the named IP access list. |
|
exit
Example:
Device(config-ipv6-acl)# exit
|
Exits IPv6 access list configuration mode and returns to global configuration mode. |
|
ipv6 prefix-list list-name permit ipv6-prefix 128
Example:
Device(config)# ipv6 prefix-list abc permit 2001:0DB8::/64 le 128
|
Creates an entry in an IPv6 prefix list. |
|
ipv6 dhcp guard policy policy-name
Example:
Device(config)# ipv6 dhcp guard policy pol1
|
Defines the DHCPv6 guard policy name and enters DHCP guard configuration mode. |
|
device-role {client | server}
Example:
Device(config-dhcp-guard)# device-role server
|
Specifies the device role of the device attached to the target (interface or VLAN). |
|
match server access-list ipv6-access-list-name
Example:
Device(config-dhcp-guard)# match server access-list acl1
|
(Optional) Enables verification of the advertised DHCP server and relay address in inspected messages from the configured authorized server access list. If not configured, this check will be bypassed. An empty access list is treated as a permit. |
|
match reply prefix-list ipv6-prefix-list-name
Example:
Device(config-dhcp-guard)# match reply prefix-list abc
|
(Optional) Enables verification of the advertised prefixes in DHCP reply messages from the configured authorized prefix list. If not configured, this check will be bypassed. An empty prefix list is treated as a permit. |
|
preference min limit
Example:
Device(config-dhcp-guard)# preference min 0
|
(Optional) Enables verification that the advertised preference (in preference option) is greater than the specified limit. If not specified, this check will be bypassed. |
|
preference max limit
Example:
Device(config-dhcp-guard)# preference max 255
|
(Optional) Enables verification that the advertised preference (in preference option) is less than the specified limit. If not specified, this check will be bypassed. |
|
trusted-port
Example:
Device(config-dhcp-guard)# trusted-port
|
(Optional) Specifies that this policy is being applied to trusted ports. All DHCP guard policing will be disabled. |
|
exit
Example:
Device(config-dhcp-guard)# exit
|
Exits DHCP guard configuration mode and returns to global configuration mode. |
|
interface type number
Example:
Device(config)# interface GigabitEthernet 0/2/0
|
Specifies an interface and enters interface configuration mode. |
|
switchport
Example:
Device(config-if)# switchport
|
Puts an interface that is in Layer 3 mode into Layer 2 mode for Layer 2 configuration. |
|
ipv6 dhcp guard [attach-policy policy-name] [vlan {add | all | all | except | none | remove} vlan-id][ ... vlan-id]]
Example:
Device(config-if)# ipv6 dhcp guard attach-policy pol1 vlan add vlan1
|
Attaches a DHCPv6 guard policy to an interface. The attach-policy and vlan keywords are optional in the interface command. If no VLAN number is specified, traffic from all VLANs on the port will be checked. |
|
exit
Example:
Device(config-if)# exit
|
Exits interface configuration mode and returns to global configuration mode. |
|
vlan vlan-id
Example:
Device(config)# vlan 1
|
Specifies a VLAN and enters VLAN configuration mode. |
|
ipv6 dhcp guard [attach-policy policy-name]
Example:
Device(config-vlan)# ipv6 dhcp guard attach-policy pol1
|
Attaches a DHCPv6 guard policy to a VLAN. |
|
exit
Example:
Device(config-vlan)# exit
|
Exits interface configuration mode and returns to global configuration mode. |
|
exit
Example:
Device(config)# exit
|
Exits global configuration mode and returns to privileged EXEC mode. |
|
show ipv6 dhcp guard policy [policy-name]
Example:
Device# show ipv6 dhcp policy guard pol1
|
(Optional) Displays the policy configuration as well as all the interfaces where the policy is applied. |