Drop IPv6 Subnet-router Anycast Address Traffic

You can enable hardware to drop IPv6 subnet-router anycast address traffic that has the all-zero subnet prefix.

About this task

By default, traffic destined for IPv6 subnet-router anycast addresses is allowed. However, you can deny the traffic for reasons such as preventing a DDoS attack. For more information, see Prevention of DDoS attack on IPv6 Subnet-router Anycast Addresses.

Procedure

  1. Access global configuration mode.
    device# configure terminal
  2. Enable hardware to drop traffic destined for IPv6 subnet-router anycast addresses.
    device(config)# ipv6 subnet-zero drop