Network security - Implement and troubleshoot IPv6 first hop security - RA guard

3 important questions on Network security - Implement and troubleshoot IPv6 first hop security - RA guard

What does the RA host mode?

In host mode all RA and router redirect messages are blocked on a port.

What does router mode and what additional options can be checked?


In router mode RA messages are allowed and there are additional options that can be checked and filtered, including:


• Advertised hop count limit
• Advertised managed address configuration flag
• IPv6 address of sender
• Advertised prefixes
• Advertised default router preference

What are the command to configure RA guard host mode on an interface?

To configure an RA guard policy to block all RAs:
Switch(config)#ipv6 nd raguard policy RAGUARD
Switch(config-ra-guard)#device-role host

And then to attach policy to an interface:
Switch(config)#int range fast0/5 - 7
Switch(config-if)#ipv6 nd raguard attach-policy RAGUARD

The question on the page originate from the summary of the following study material:

  • A unique study and practice tool
  • Never study anything twice again
  • Get the grades you hope for
  • 100% sure, 100% understanding
Remember faster, study better. Scientifically proven.
Trustpilot Logo