Reset Search
 

 

Article

How to configure policy to drop or block IPV6 packets on Securestacks and Modular switches/routers

« Go Back

Information

 
TitleHow to configure policy to drop or block IPV6 packets on Securestacks and Modular switches/routers
Objective
How to configure policy to drop or block IPV6 packets on Securestacks and Modular switches/routers
Environment
  • K-Series
  • S-Series
  • Securestack
  • B5-Series
  • C5-Series
  • 7100-Series
  • All firmware versions
Procedure
  • On S/K and 7100-Series, policy can be applied dynamically instead of a per-port basis with the following config (not a supported config via policy manager):
  • set policy profile 66 name dropIPv6 pvid-status enable pvid 0
    set policy rule admin-profile ether 0x86dd mask 16 admin-pid 66
  • On C5-Series/B5-Series Securestack, we can only apply on a per-port profile:
  • set policy profile 66 name dropIPv6 pvid-status enable pvid 4095
    set policy rule 66 ether 0x86DD mask 16 drop
    set policy port *.*.* 66
  • This C5-Series/B5-Series policy can also be applied to our K-Chassis, but forces every port to be assigned to this policy instead of dynamically being assigned to all traffic
  • On 7100-Series, policy can be applied dynamically instead of a per-port basis with the following config
  • Ensure there is no previously configured policy prior to configuring this
Additional notes

Feedback

 

Was this article helpful?


   

Feedback

Please tell us how we can make this article more useful.

Characters Remaining: 255