Security e-Series
1755748 Members
4225 Online
108837 Solutions
New Discussion

IPv6: RA-Guard on HPE/Aruba 54xx Series - Whitelist allowed routers

 
hungryduck
Occasional Contributor

IPv6: RA-Guard on HPE/Aruba 54xx Series - Whitelist allowed routers

Hey Folks,

we'd like to implement the RA Guard Feature to put more security into our IPv6 environment. As read in the documentation, there's only the possibility, to block router advertisements on specified ports:

Syntax: [no] ipv6 ra-guard ports <port-list> [log]

Enables or disable RA Guard on the specified ports, which
blocks IPv6 router advertisements and router redirects.

The no form of the command disables RA Guard.

[log]: Enables debug logging of RA and redirects packets to
debug output.

I can't find a param to define an allow/whitelist router, to say: "RAs/IPv6 Addresses from this device are Ok".

Thanks in advance for your suggestions.

Best regards,
Matthias