dhcpv6 snooping alarm (interface view)

Function

The dhcpv6 snooping alarm enable command enables dropped packets alarm.

The undo dhcpv6 snooping alarm enable command disables dropped packets alarm.

The dhcpv6 snooping alarm threshold command configures an alarm threshold for the number of dropped packets in the interface.

The undo dhcpv6 snooping alarm threshold command restores the default setting.

By default:

- The function of dropped packets alarm is disabled.

- The alarm threshold for the number of dropped packets in the interface is a global alarm threshold (which is 100 by default and can be configured manually).

Format

dhcpv6 snooping alarm ipv6 enable

dhcpv6 snooping alarm ipv6 threshold threshold-value

undo dhcpv6 snooping alarm ipv6 enable

undo dhcpv6 snooping alarm ipv6 threshold [ threshold-value ]

Parameters

Parameter Description Value
ipv6

Indicates the alarm threshold for the number of dropped IPv6 packets that mismatch any entry in the binding table.

-

enable

Alarm enable.

-

threshold threshold-value

Specifies an alarm threshold.

The value is an integer ranging from 1 to 1000, in seconds.

Views

100GE interface view, 10GE interface view, 25GE interface view, 400GE interface view, 40GE interface view, 50GE interface view, Eth-Trunk interface view, FlexE sub-interface view, FlexE interface view, GE optical interface view, GE interface view, GE electrical interface view, Global VE sub-interface view, VE sub-interface view, Sub-interface view

Default Level

2: Configuration level

Task Name and Operations

Task Name Operations
dhcp write

Usage Guidelines

Usage Scenario

In DHCPv6 applications, configure the packet alarm function as follows:

If IPv6/MAC spoofing attacks exists and IPv6 packet check is configured, you can configure the IPv6 packet alarm function. When the number of discarded IPv6 packets exceeds a specified alarm threshold, the system generates an alarm and notifies the NMS of the alarm.

Prerequisites

The dhcpv6 snooping enable command to enable DHCPv6 snooping globally.

Precautions

After the trap function is enabled for discarded packets on an interface, if the interface threshold is not configured, the global threshold is used. If the interface threshold is configured, the interface threshold is preferentially used.

Example

# Enable the invalid IPv6 packet alarm on GE 0/1/0.
<HUAWEI> system-view
[~HUAWEI] dhcpv6 snooping enable
[*HUAWEI] interface GigabitEthernet 0/1/0
[*HUAWEI-GigabitEthernet0/1/0] dhcpv6 snooping enable
[*HUAWEI-GigabitEthernet0/1/0] dhcpv6 snooping alarm ipv6 enable
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
Next topic >