![Cisco 350XG series Administration Manual Download Page 525](http://html.mh-extra.com/html/cisco/350xg-series/350xg-series_administration-manual_67491525.webp)
Security: IPv6 First Hop Security
Neighbor Binding Integrity
Cisco 350XG & 550XG Series 10G Stackable Managed Switches
506
24
A separate, independent instance of NB Integrity runs on each VLAN on which the
feature is enabled.
Learning Advertised IPv6 Prefixes
NB Integrity learns IPv6 prefixes advertised in RA messages and saves it in the
Neighbor Prefix table. The prefixes are used for verification of assigned global
IPv6 addresses.
By default, this validation is disabled. When it is enabled, addresses are validated
against the prefixes in the
page.
Static prefixes used for the address validation can be added in the
page.
Validation of Global IPv6 Addresses
NB Integrity performs the following validations:
•
If the target address in an NS or NA message is a global IPv6 address, it
must belong to one of the prefixes defined in the RA Prefix table.
•
A global IPv6 address provided by a DHCPv6 server must belong to one of
the prefixes defined in the IPv6 Prefix List (in
page).
If a message does not pass this verification, it is dropped and a rate limited
SYSLOG message is sent.
Neighbor Binding Table Overflow
When there is no free space to create a new entry, no entry is created and a
SYSLOG message is sent.
Establishing Binding of Neighbors
An IPv6 First Hop Security switch can discover and record binding information by
using the following methods:
•
NBI-NDP Method
: Learning IPv6 addresses from the snooped Neighbor
Discovery Protocol messages
•
NBI-DHCP method
: By learning IPv6 addresses from the snooped DHCPv6
messages