hardMultiple Select
How to Configure IPv6 RA Guard: Create Policy and Attach to Interface
Which TWO configuration steps are required to enable IPv6 RA Guard on a Cisco switch interface? (Choose TWO.)
Quick Answer
The answer is that you must first create an RA Guard policy defining the device role (router or host) and then apply that policy to the interface using the 'ipv6 nd raguard attach-policy POLICY_NAME' command. This two-step process is required because RA Guard does not function as a simple on/off toggle; the policy dictates which router advertisement messages are trusted or dropped based on the interface’s role, preventing rogue RA attacks. On the Cisco CCNP ENARSI 300-410 exam, this topic tests your understanding of IPv6 First Hop Security features, and a common trap is assuming that enabling 'ipv6 nd raguard' alone is sufficient—it is not, as the policy attachment is mandatory. To remember, think of RA Guard as a bouncer: you must write the guest list (the policy) before telling the bouncer which door to guard (the interface).
⚠ Common exam trap
Cisco often tests that RA Guard requires both a policy creation and an interface attachment, leading candidates to mistakenly think a simple interface command or global routing enablement is sufficient.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an RA Guard policy using the 'ipv6 nd raguard policy POLICY_NAME' command.
Option A is correct because RA Guard on Cisco switches requires first defining a policy in global configuration mode with the 'ipv6 nd raguard policy POLICY_NAME' command, which creates the policy container where device-role and other parameters are set. Option B is correct because the policy must then be bound to the specific Layer 2 switch interface using the interface-level command 'ipv6 nd raguard attach-policy POLICY_NAME' for the filtering to take effect. Option C is not required because RA Guard is a Layer 2 security feature that filters ICMPv6 Router Advertisement messages at the switch port and does not depend on the switch having IPv6 unicast routing enabled. Option D is incorrect because there is no direct interface command 'ipv6 nd raguard' that enables the feature without an associated policy. Option E is incorrect because DHCPv6 Guard is a separate feature that filters DHCPv6 server/client messages and is not a prerequisite for RA Guard.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an RA Guard policy using the 'ipv6 nd raguard policy POLICY_NAME' command.
Why this is correct
Creating the RA Guard policy with `ipv6 nd raguard policy POLICY_NAME` is mandatory because the feature cannot be attached to an interface without a defined policy. The policy holds the device-role and host-access parameters that determine which Router Advertisement messages are filtered, satisfying the stem's requirement for enabling RA Guard on the interface.
- ✓
Apply the RA Guard policy to the interface with the 'ipv6 nd raguard attach-policy POLICY_NAME' command.
Why this is correct
Attaching the policy with `ipv6 nd raguard attach-policy POLICY_NAME` activates RA Guard on the target interface, satisfying the stem's requirement to enable the feature at the port level. Policy creation alone does nothing until bound; this command performs that binding, filtering rogue IPv6 Router Advertisement messages.
- ✗
Enable IPv6 routing globally with 'ipv6 unicast-routing'.
Why it's wrong here
Global IPv6 unicast routing is not required for RA Guard; the feature operates at Layer 2 on the interface and is enabled per-port with 'ipv6 nd raguard policy' and attachment. It tempts because routing is needed for IPv6 forwarding generally. RA Guard is correct when blocking rogue RAs on access ports.
- ✗
Configure 'ipv6 nd raguard' directly on the interface without a policy.
Why it's wrong here
RA Guard requires a policy defined in global configuration and then attached to the interface; the interface-level command alone is not the supported syntax. It is tempting because many interface features are enabled with a single command, and a policy would be the correct approach when applying differentiated blocking or monitoring behaviour across multiple ports.
- ✗
Enable DHCPv6 Guard on the same interface to complement RA Guard.
Why it's wrong here
DHCPv6 Guard filters rogue DHCPv6 servers and is unrelated to RA Guard's function of blocking unauthorised router advertisements; enabling it is not a required step. It is tempting because both are IPv6 first-hop security features often deployed together, and DHCPv6 Guard would be correct when the requirement is preventing rogue DHCPv6 servers.
Go deeper
Related to this question
About these practice questions
One of 1,401 original 300-410 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on 300-410
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A network engineer runs the following command to troubleshoot an IPv6 First Hop Security issue: R1# debug ipv6 nd raguard *Mar 1 00:01:23.456: IPv6-ND-RA-Guard: R1, Fa0/0, RA received on port Fa0/0, src fe80::1, dst ff02::1 *Mar 1 00:01:23.456: IPv6-ND-RA-Guard: R1, Fa0/0, RA from fe80::1 is allowed by policy TRUSTED *Mar 1 00:01:24.789: IPv6-ND-RA-Guard: R1, Fa0/0, RA received on port Fa0/0, src fe80::2, dst ff02::1 *Mar 1 00:01:24.789: IPv6-ND-RA-Guard: R1, Fa0/0, RA from fe80::2 is blocked by policy UNTRUSTED What does this output indicate?
medium- ✓ A.RA Guard is configured with a policy that trusts fe80::1 and blocks fe80::2, preventing rogue RA attacks.
- B.RA Guard is blocking all RAs regardless of source, indicating a misconfiguration.
- C.RA Guard is allowing all RAs but logging them for analysis.
- D.RA Guard is not configured; the debug output is from default IPv6 ND behavior.
Why A: The debug output shows that RA Guard is actively filtering Router Advertisement (RA) messages on interface Fa0/0. The first RA from fe80::1 is explicitly allowed by a policy named TRUSTED, while the second RA from fe80::2 is blocked by a policy named UNTRUSTED. This confirms that RA Guard is correctly configured to permit only authorized routers (fe80::1) and block potential rogue RA sources (fe80::2), preventing RA-based attacks in an IPv6 First Hop Security deployment.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 300-410 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 300-410 exam.