436
To identify forged ND packets, HP developed the source MAC consistency check and ND detection
features.
NOTE:
For more information about the functions of the ND protocol, see
Layer 3—IP Services Configuration
Guide.
Enabling source MAC consistency check for ND
packets
Use source MAC consistency check on a gateway to filter out ND packets that carry different source
MAC addresses in the Ethernet frame header and the source link layer address option.
CAUTION:
If VRRP is used, disable source MAC consistency check for ND packets to prevent incorrect dropping of
packets. With VRRP, the NA message always conveys a MAC address different than the Source Link-
Layer Address option.
To enable source MAC consistency check for ND packets:
To do…
Command…
Remarks
1.
Enter system view.
system-view
—
2.
Enable source MAC consistency
check for ND packets.
ipv6 nd mac-check enable
Required
Disabled by default