![Cisco 350XG series Administration Manual Download Page 550](http://html.mh-extra.com/html/cisco/350xg-series/350xg-series_administration-manual_67491550.webp)
Security: IPv6 First Hop Security
Configuring IPv6 First Hop Security through Web GUI
Cisco 350XG & 550XG Series 10G Stackable Managed Switches
531
24
-
DHCP
—Learnt from DHCPv6 protocol messages.
•
State
—State of the entry:
-
Tentative
—The new host IPv6 address is under validation. Since its
lifetime is less than 1 sec its expiration time is not displayed.
-
Valid
—The host IPv6 address was bound.
•
Expiry Time (Sec.)
—Remaining time in seconds until the entry will be
removed, if it is not confirmed.
•
TCAM Overflow
—Entries marked as
No
have not been added to the TCAM
because TCAM overflow
STEP 3
To add a policy, click
Add
and enter the following fields:
•
VLAN ID
—VLAN ID of the entry.
•
IPv6 Address
—Source IPv6 address of the entry.
•
Interface
— Port on which packet is received.
•
MAC Address
— Neighbor MAC address of the packet.
Neighbor Prefix Table
You can add static prefixes for global IPv6 addresses bound from NDP messages
in the Neighbor Prefix table. Dynamic entries are learned. as described in
Learning Advertised IPv6 Prefixes
To add entries to the Neighbor Prefix table:
STEP 1
Click
Security
>
IPv6 First Hop Security
>
Neighbor Prefix Table.
STEP 2
Select one of the following options for clearing the Neighbor Prefix table:
•
Static Only
—Clear only static entries.
•
Dynamic Only
—Clear only dynamic entries.
•
All Dynamic & Static
—Clear static and dynamic entries.
STEP 3
The following fields are displayed for the exiting entries:
•
VLAN ID
—VLAN on which the prefixes are relevant.