The ipv6 nd multicast-suppress dynamic limit command configures the maximum number of dynamic proxy ND entries that can be learned in a BD.
The undo ipv6 nd multicast-suppress dynamic limit command restores the default configuration.
By default, a maximum of 256 dynamic proxy ND entries can be learned in a BD.
Usage Scenario
When an illegitimate user sends a large number of RA messages to attack a device, the device may learn a lot of dynamic proxy ND entries within a short period of time. As a result, the CPU usage increases sharply and a lot of memory resources are used, which prevents legitimate users from accessing network resources. To effectively prevent overflow of dynamic proxy ND entries, run the ipv6 nd multicast-suppress dynamic limit command to configure the maximum number of dynamic proxy ND entries that can be learned in a BD.
Prerequisites
NS multicast suppression has been enabled using the ipv6 nd multicast-suppress { proxy-reply [ unknown-options-unicast ] | unicast-forward } [ mismatch-discard ] enable command in the BD view.