< Home

nd raguard log enable

Function

The nd raguard log enable command enables the IPv6 RA guard log function.

The nd raguard log enable command disables the IPv6 RA guard log function.

By default, the IPv6 RA guard log function is disabled.

Format

nd raguard log enable

undo nd raguard log enable

Parameters

None.

Views

System view

Default Level

2: Configuration level

Usage Guidelines

The IPv6 RA guard log function records RA message processing information to meet the audit requirements of administrators. After this function is enabled, the device generates the ND_RAGUARD/3/ND_RAGUARD_DROP log when detecting invalid RA messages. The log content includes the name of the attacked interface, source IP address and source MAC address of RA messages, and total number of RA messages discarded on the interface.

The IPv6 RA guard logs generated by the device are sent to the information center module for processing. The configuration of the information center module determines the output rules and output directions of the logs. For details about the information center, see Information Center Configuration in the S2720, S5700, and S6700 V200R019C10 Configuration Guide - Device Management.

Example

# Enable the IPv6 RA guard log function.

<HUAWEI> system-view
[HUAWEI] nd raguard log enable
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >