![Cisco 350XG series Administration Manual Download Page 529](http://html.mh-extra.com/html/cisco/350xg-series/350xg-series_administration-manual_67491529.webp)
Security: IPv6 First Hop Security
Attack Protection
Cisco 350XG & 550XG Series 10G Stackable Managed Switches
510
24
•
Stateless address configuration
A malicious host could send RA messages advertising itself as an IPv6 router and
providing
counterfeit prefixes for
stateless address configuration.
RA Guard provides protection against such attacks by configuring the interface
role as a host interface for all interfaces where IPv6 routers cannot be connected.
Protection against IPv6 Address Resolution Spoofing
A malicious host could send NA messages advertising itself as an IPv6 Host
having the given IPv6 address.
NB Integrity provides protection against such attacks in the following ways:
•
If the given IPv6 address is unknown, the Neighbor Solicitation (NS)
message is forwarded only on inner interfaces.
•
If the given IPv6 address is known, the NS message is forwarded only on
the interface to which the IPv6 address is bound.
•
A Neighbor Advertisement (NA) message is dropped if the target IPv6
address is bound with another interface.
Protection against IPv6 Duplication Address Detection
Spoofing
An IPv6 host must perform Duplication Address Detection for each assigned IPv6
address by sending a special NS message (Duplicate Address Detection
Neighbor Solicitation message (DAD_NS) message).
A malicious host could send reply to a DAD_NS message advertising itself as an
IPv6 host having the given IPv6 address.
NB Integrity provides protection against such attacks in the following ways:
•
If the given IPv6 address is unknown, the DAD_NS message is forwarded
only on inner interfaces.
•
If the given IPv6 address is known, the DAD_NS message is forwarded only
on the interface where the IPv6 address is bound.
•
An NA message is dropped if the target IPv6 address is bound with another
interface.