09-Security Command Reference

HomeSupportResource CenterSwitchesS12500X-AF SeriesS12500X-AF SeriesTechnical DocumentsReference GuidesCommand ReferencesH3C S12500X-AF Switch Series Command References(R28xx)-6W10009-Security Command Reference
20-SAVI commands
Title Size Download
20-SAVI commands 39.64 KB

SAVI commands

ipv6 savi down-delay

Use ipv6 savi down-delay to set the entry deletion delay.

Use undo ipv6 savi down-delay to restore the default.

Syntax

ipv6 savi down-delay delay-time

undo ipv6 savi down-delay

Default

The entry deletion delay is 30 seconds.

Views

System view

Predefined user roles

network-admin

mdc-admin

Parameters

delay-time: Specifies the entry deletion delay in the range of 0 to 21474836 seconds.

Usage guidelines

The entry deletion delay is the period of time that the device waits before deleting the DHCPv6 snooping entries and ND snooping entries for a down port.

Examples

# Set the entry deletion delay to 100 seconds.

<Sysname> system-view

[Sysname] ipv6 savi down-delay 100

ipv6 savi log enable

Use ipv6 savi log enable to enable filtering entry logging.

undo ipv6 savi log enable to disable filtering entry logging.

Syntax

ipv6 savi log enable filter-entry

undo ipv6 savi log enable filter-entry

Default

Filtering entry logging is disabled.

Views

System view

Predefined user roles

network-admin

mdc-admin

Parameters

filter-entry: Enables filtering entry logging.

Usage guidelines

Filtering entries are effective bindings used for filtering IPv6 packets by the source IPv6 address. Filtering entry logging enables the device to generate log messages for filtering entries. A log message contains the IPv6 address, MAC address, VLAN, and interface of a filtering entry.

The device sends filtering entry log messages to the information center. With the information center, you can set log message filtering and output rules, including output destinations. For more information about using the information center, see Network Management and Monitoring Configuration Guide.

Examples

# Enable filtering entry logging.

<Sysname> system-view

[Sysname] ipv6 savi log enable filter-entry

ipv6 savi strict

Use ipv6 savi strict to enable Source Address Validation Improvement (SAVI).

Use undo ipv6 savi strict to disable SAVI.

Syntax

ipv6 savi strict

undo ipv6 savi strict

Default

SAVI is disabled.

Views

System view

Predefined user roles

network-admin

mdc-admin

Examples

# Enable SAVI.

<Sysname> system-view

[Sysname] ipv6 savi strict

Related commands

ipv6 verify source

  • Cloud & AI
  • InterConnect
  • Intelligent Computing
  • Security
  • SMB Products
  • Intelligent Terminal Products
  • Product Support Services
  • Technical Service Solutions
All Services
  • Resource Center
  • Policy
  • Online Help
All Support
  • Become a Partner
  • Partner Resources
  • Partner Business Management
All Partners
  • Profile
  • News & Events
  • Online Exhibition Center
  • Contact Us
All About Us
新华三官网