Security: IPv6 First Hop Security
Configuring IPv6 First Hop Security through Web GUI
Cisco Sx350, SG350X, SG350XG, Sx550X & SG550XG Series Managed Switches, Firmware Release 2.2.5.x
558
25
-
User Defined
—Verifies that the advertised preference value is less than or equal to
this value.
STEP 3
Click
Apply
to add the settings to the Running Configuration file.
The existing policies are displayed. The fields are displayed below except for the
Policy Type
field. This displays whether the policy is user-defined or a default one.
STEP 4
If required, click
Add
to create a DHCPv6 policy.
STEP 5
Enter the following fields:
•
Policy Name
—Enter a user-defined policy name.
•
Device Role
—Select either
Server
or
Client
to specify the role of the device attached
to the port for DHCPv6 Guard.
-
Inherited
—Role of device is inherited from either the VLAN or system default
(client).
-
Client
—Role of device is client.
-
Server
—Role of device is server.
•
Match Reply Prefixes
—Select to enable verification of the advertised prefixes in
received DHCP reply messages within a DHCPv6 Guard policy.
-
Inherited
—Value is inherited from either the VLAN or system default (no
verification).
-
No Verification
—Advertised prefixes are not verified.
-
Match List
— IPv6 prefix list to be matched.
•
Match Server Address
—Select to enable verification of the DHCP server's and relay’s
IPv6 address in received DHCP reply messages within a DHCPv6 Guard policy.
-
Inherited
—Value is inherited from either the VLAN or system default (no
verification).
-
No Verification
—Disables verification of the DHCP server's and relay’s IPv6
address.
-
Match List
— IPv6 prefix list to be matched.
•
Minimal Preference
—This field indicates whether the DHCPv6 Guard policy will
check the minimum advertised preference value of the packet received.
-
Inherited
—Minimal preference is inherited from either the VLAN or system default
(client).