To configure RA filtering on an OmniSwitch VLAN site

Purpose

Perform this procedure to configure RA (Router Advertisement) filtering that can be used to prevent the spread of unwanted RAs from unauthorized systems. Once enabled on an interface, any received RAs will be dropped without being forwarded to other connected IPv6 clients. One or more trusted ports or link aggregation group members can be specified for an interface. RAs received on these trusted ports or link aggregation group members will be allowed to continue on to all other IPv6 clients reached via the interface.

Note: You can configure RA filtering only after the VLAN site is created. RA filtering cannot be enabled on a VLAN site that is used as an OpenFlow VLAN, Ethernet service VLAN, mirrored port, or IPM VLAN.

Steps
 

Choose Manage→Service→Services from the NFM-P main menu. The Manage Services form opens.


Choose an OmniSwitch VLAN service and click Properties. The VLAN Service Name (Edit) form opens.


On the service navigation tree, right-click on the site on which you need to configure RA filtering parameters. The Site (Edit) form opens.


Click on the RA Filter tab. By default, the RA Filter Status parameter is set to Disabled.

If you are configuring the RA Filter for 6900/6860/6865/6465, an additional RA Filter Interface parameter is displayed.


Choose Enable from the drop-down menu.

If you are configuring the RA Filter for 6900/6860/6865/6465, enter the RA Filter Interface name. The RA Filter status can be enabled only if the RA Filter Interface name is entered. Providing the RA Filter Interface name along with the RA Filter in enabled status will create a default IPv6 interface on the node.


Click on the Trusted Ports/LAGs tab.


Click on the Create tab and configure RA filtering on the trusted ports/LAGs. By default, all the ports/LAGs are untrusted.


Click Apply to save the changes and close the form.

End of steps