SNR S2989G-48TX-DC — настройка безопасности IPv6: руководство по конфигурации RA [545/553]

Превью страниц Страница 545 / 553
SNR S2989G-24TX [545/553] Ipv6 security ra configuration task sequence
S2989G-24TX Operation Manual
Chapter 11 IPv6 Configuration
11-35
Ensure there is a vlan configured as a L2 general querier, or there
is a static mrouter configured in a segment,
Use command to check if the MLD snooping information is correct
11.6
IPv6 Security RA
11.6.1
Introduction to IPv6 Security RA
In IPv6 networks, the network topology is generally compromised of routers, layer-
two switches and IPv6 hosts. Routers usually advertise RA, including link prefix, link MTU
and other information, when the IPv6 hosts receive RA, they will create link address, and
set the default router as the one sending RA in order to implement IPv6 network
communication. If a vicious IPv6 host sends RA to cause that normal IPv6 users set the
default router as the vicious IPv6 host user, the vicious user will be able to capture the
information of other users, which will threat the network security. Simultaneously, the
normal users get incorrect address and will not be able to connect to the network. So, in
order to implement the security RA function, configuring on the switch ports to reject
vicious RA messages is necessary, thus to prevent forwarding vicious RA to a certain
extent and to avoid affecting the normal operation of the network.
11.6.2
IPv6 Security RA Configuration Task Sequence
1. Globally enable IPv6 security RA
2. Enable IPv6 security RA on a port
3. Display and debug the relative information of IPv6 security RA
1. Globally enable IPv6 security RA
Command
Explanation
Global Configuration Mode
ipv6 security-ra enable
no ipv6 security-ra enable
Globally enable and disable IPv6 security
RA.
2. Enable IPv6 security RA on a port
Command
Explanation
Port Configuration Mode
ipv6 security-ra enable
no ipv6 security-ra enable
Enable and disable IPv6 security RA in
port configuration mode.

Содержание

666

Изучите важные аспекты настройки безопасности IPv6, включая управление RA и защиту сети от вредоносных атак. Узнайте, как правильно настроить порты для повышения безопасности.