To prevent IPv6/MAC spoofing attacks on a device, you can enable the packet check function on the device. Upon receipt of an IPv6 packet, the device checks whether the source IPv6 address and source MAC address of the IPv6 packet match an entry in the DHCPv6 snooping binding table.
After DHCPv6 snooping is enabled, binding entries are automatically generated when DHCPv6 users go online. If DHCPv6 users are statically assigned IPv6 addresses, you need to manually configure static binding entries for the users.
The system view is displayed.
The interface view is displayed.
The IPv6 packet check function is enabled on the interface.
The configuration is committed.