< Home

nd raguard policy

Function

The nd raguard policy command creates an IPv6 RA guard policy and displays the IPv6 RA guard policy view.

The undo nd raguard policy command deletes a created IPv6 RA guard policy.

By default, no IPv6 RA guard policy is created.

Format

nd raguard policy policy-name

undo nd raguard policy policy-name

Parameters

Parameter Description Value

policy-name

Specifies the name of an IPv6 RA guard policy.

The value is a string of 1 to 31 case-insensitive characters.

Views

System view

Default Level

2: Configuration level

Usage Guidelines

Usage Scenario

You can configure an IPv6 RA guard policy for an interface to filter RA messages in the following situations:

  • The type of the device or terminal connected to the interface cannot be determined. That is, no interface role can be configured for the interface to help determine whether to discard or forward RA messages.
  • The interface is connected to a router and needs to filter RA messages based on specific conditions instead of forwarding RA messages immediately.

Follow-up Procedure

Configure a matching rule in the IPv6 RA guard policy view and run the nd raguard attach-policy command to apply the IPv6 RA guard policy to an interface.

Example

# Create an IPv6 RA guard policy named p1.

<HUAWEI> system-view
[HUAWEI] nd raguard policy p1
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >