Security: IPv6 First Hop Security
Configuring IPv6 First Hop Security through Web GUI
Cisco 350, 350X and 550X Series Managed Switches, Firmware Release 2.4, ver 0.4
470
26
Neighbor Prefix Table
You can add static prefixes for global IPv6 addresses bound from NDP messages in the
Neighbor Prefix table. Dynamic entries are learned. as described in
To add entries to the Neighbor Prefix table:
STEP 1
Click
Security
>
IPv6 First Hop Security
>
Neighbor Prefix Table.
STEP 2
Select one of the following options in the
Clear Table
field to clear the Neighbor Prefix table:
•
Static Only
—Clear only static entries.
•
Dynamic Only
—Clear only dynamic entries.
•
All Dynamic & Static
—Clear static and dynamic entries.
STEP 3
The following fields are displayed for the exiting entries:
•
VLAN ID
—VLAN on which the prefixes are relevant.
•
IPv6 Prefix
—IPv6 prefix.
•
Prefix Length
—IPv6 prefix length.
•
Origin
—Entry is dynamic (learned) or static (manually configured).
•
Autoconfig
—The prefix can be used for stateless configuration.
•
Expiry Time (Sec)
—Length of time entry will remain before being deleted.
STEP 4
Click
Add
to add a new entry to the table and enter the above fields for the new entry.
FHS Status
To display the global configuration for the FHS features:
STEP 1
Click
Security
>
IPv6 First Hop Security
>
FHS Status.
STEP 2
Select a port, LAG or VLAN for which the FHS state is reported.
STEP 3
The following fields are displayed for the selected interface:
•
FHS Status