47-46
Software Configuration Guide—Release 15.0(2)SG
OL-23818-01
Chapter 47 Configuring Network Security with ACLs
Configuring RA Guard
!
interface GigabitEthernet1/1
ipv6 nd raguard
end
The following example shows a sample output of the show ipv6 commands:
Switch# show ipv6 snooping counters int gi 2/48
Received messages on Gi2/48:
Protocol Protocol message
ICMPv6 RS RA NS NA REDIR CPS CPA
0 0 0 0 0 0 0
Bridged messages from Gi2/48:
Protocol Protocol message
ICMPv6 RS RA NS NA REDIR CPS CPA
0 0 0 0 0 0 0
Dropped messages on Gi2/48:
Feature/Message RS RA NS NA REDIR CPS CPA
Dropped reasons on Gi2/48:
Switch#
Note Beginning with Cisco IOS Release 15.0(2)SG, per port RA Guard ACL statistics are supported and
displayed when you enter a show ipv6 snooping counters interface command. (Previous to this release,
you enter the show ipv6 first-hop counters interface command.)
Note Be aware that only RA (Router Advertisement) and REDIR (Router Redirected packets) counters are
supported in 12.2(54)SG.
Switch# show ipv6 first-hop policies
RA guard policies configured:
Policy Interface Vlan
------ --------- ----
default Gi2/48 all
Switch#
Usage Guidelines
Observe the following restrictions:
RA Guard is an ingress feature; only IPv6 Router-Advertisement and Router-Redirect packets
entering through the port are filtered.
RA Guard does not offer protection in environments where IPv6 traffic is tunneled.
This feature is supported only in hardware; packets are not punted to software except under resource
exhaustion (for example, TCAM memory exhaustion).