The dhcpv6 snooping nomatch-packet ipv6 action forward command configures a forward policy as the matching rule of the DHCPv6 snooping binding table for IPv6 packets.
The undo dhcpv6 snooping nomatch-packet ipv6 action forward command restores the discard policy for checking IPv6 packets against the DHCPv6 snooping binding table.
By default, a discard policy is used to check whether global IPv6 packets match the DHCPv6 snooping binding table.
Usage Scenario
In DHCPv6 applications, if IPv6/MAC spoofing attacks occurs, you can configure the device to check IPv6 packets by determining whether the source IPv6 address and source MAC address in IPv6 packets match entries in the DHCPv6 snooping binding table. The rules for checking whether IPv6 packets match entries in the DHCPv6 snooping binding table are classified into discard and forward policies.
Prerequisites
DHCPv6 snooping has been enabled globally using the dhcpv6 snooping enable command.