Security: IPv6 First Hop Security
DHCPv6 Guard
543
Cisco Sx350, SG350X, SG350XG, Sx550X & SG550XG Series Managed Switches, Firmware Release 2.2.5.x
25
Message Validation
ND Inspection validates the Neighbor Discovery protocol messages, based on an ND
Inspection policy attached to the interface. This policy can be defined in the
page.
If a message does not pass the verification defined in the policy, it is dropped and a rate limited
SYSLOG message is sent.
Egress Filtering
ND Inspection blocks forwarding of RS and CPS messages on interfaces configured as host
interfaces.
DHCPv6 Guard
DHCPv6 Guard treats the trapped DHCPv6 messages. DHCPv6 Guard supports the following
functions:
•
Filtering of received DHCPv6 messages.
DHCP Guard discards DHCPv6 reply messages received on interfaces whose role is
client. The interface role is configured in the
page.
•
Validation of received DHCPv6 messages.
DHCPv6 Guard validates DHCPv6 messages that match the filtering based on the
DHCPv6 Guard policy attached to the interface.
If a message does not pass verification, it is dropped. If the logging packet drop configuration
on the FHS common component is enabled, a rate limited SYSLOG message is sent.
Neighbor Binding Integrity
Neighbor Binding (NB) Integrity establishes binding of neighbors.
A separate, independent instance of NB Integrity runs on each VLAN on which the feature is
enabled.