Command Line Reference
Security Configuration
SAVI Configuration
5 min
savi configuration savi configuration show savi config show savi config \[command] show savi config \[purpose] view savi function configuration information \[view] system view \[use cases] sonic# show savi config + + + \| interfaces | check mode | +==============+=============+ \| vlan100 | false | + + + \| vlan200 | true | + + + savi enable savi enable \[command] savi enable no savi enable \[purpose] enable the savi detection function of the interface \[view] vlan view \[notes] after enabling savi function, the device will compare the source ip, source mac, snooping table entry and user bind table entry of the received nd protocol packets, dhcpv6 protocol packets, and if it can hit, the packets will be passed, otherwise the packets will be dropped \[use cases] sonic(config)# vlan 100 sonic(config vlan 100)# savi enable savi trusted interface savi trusted interface \[command] savi trusted interface vlan vlan id no savi trusted interface vlan vlan id \[purpose] configuring savi trusted ports \[view] vlan view \[notes] after configured as a savi trusted port, nd protocol packets and dhcpv6 protocol packets received from this port will not be checked by savi and will all be allowed to pass \[use cases] sonic(config)# interface ethernet 1 sonic(config if 1)# savi trusted interface vlan 10 savi alarm enable savi alarm enable \[command] savi alarm enable savi alarm threshold alarm threshold \[purpose] enable the packet inspection alarm function \[view] interface view \[notes] when this feature is enabled, when the packets discarded on the device due to the packet inspection function exceed the alarm threshold, a log is recorded \[use cases] sonic(config)# interface ethernet 1 sonic(config if 1)# savi alarm enable
