Security: IPv6 First Hop Security
Configuring IPv6 First Hop Security through Web GUI
Cisco 350, 350X and 550X Series Managed Switches, Firmware Release 2.4, ver 0.4
456
26
•
Router Solicitation (RS) messages
•
Neighbor Advertisement (NA) messages
•
Neighbor Solicitation (NS) messages
•
ICMPv6 Redirect messages
•
Certification Path Advertisement (CPA) messages
•
Certification Path Solicitation (CPS) message
•
DHCPv6 messages
The FHS features are disabled by default.
Configuring IPv6 First Hop Security through Web GUI
FHS Settings
Use the FHS Settings page to enable the FHS Common feature on a specified group of VLANs
and to set the global configuration value for logging of dropped packets. If required, a policy
can be added or the packet drop logging can be added to the system-defined default policy.
To configure IPv6 First Hop Security common parameters:
STEP 1
Click
Security
>
IPv6 First Hop Security
>
FHS Settings
.
The currently-defined polices are displayed. For each policy, its
Policy Type
is displayed,
which indicates whether it is a default or user-defined policy.
STEP 2
Enter the following global configuration fields:
•
FHS VLAN List
—Enter one or more VLANs on which IPv6 First Hop Security is
enabled.
•
Packet Drop Logging
—Select to create a SYSLOG when a packet is dropped by a First
Hop Security policy. This is the global default value if no policy is defined.
STEP 3
Click
Apply
to add the settings to the Running Configuration file.
STEP 4
Create a FHS policy if required by clicking
Add
.
Enter the following fields:
•
Policy Name
—Enter a user-defined policy name.