Configuring a CGA IPv6 Address

To enable IPv6 SEND to protect ND messages that carry CGA and RSA options, you need to configure a CGA IPv6 address on an interface that sends ND messages.

Procedure

  1. Run system-view

    The system view is displayed.

  2. Run rsa key-pair label label-name modulus modulus-bits

    An RSA key pair is created.

  3. Run interface interface-type interface-number

    The view of the interface where a CGA IPv6 address needs to be configured is displayed.

  4. Run ipv6 enable

    The IPv6 function is enabled.

  5. Run ipv6 security rsakey-pair key-label

    The RSA key pair is bound to the interface to generate a CGA address.

  6. Run ipv6 security modifier sec-level sec-value [ modifier-value ]

    The modifier value and security level are configured for the CGA address.

    The modifier value can be manually configured only when the security level of the CGA address is 0.

  7. Run ipv6 address { ipv6-address prefix-length | ipv6-address/prefix-length } cga or ipv6 address ipv6-address link-local cga

    A CGA IPv6 address is configured.

  8. Run commit

    The configuration is committed.

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
Next topic >