Drop IPv6 Subnet-router Anycast Address Traffic

By default, traffic destined for IPv6 subnet-router anycast addresses is allowed. However, you can deny the traffic for reasons such as preventing a DDoS attack. For more information, see Prevention of DDoS attack on IPv6 Subnet-router Anycast Addresses.
  1. Access global configuration mode.
    device# configure terminal
  2. Enable hardware to drop traffic destined for IPv6 subnet-router anycast addresses.
    device(config)# ipv6 subnet-zero drop