![Cisco 350XG series Скачать руководство пользователя страница 531](http://html.mh-extra.com/html/cisco/350xg-series/350xg-series_administration-manual_67491531.webp)
Security: IPv6 First Hop Security
Policies, Global Parameters and System Defaults
Cisco 350XG & 550XG Series 10G Stackable Managed Switches
512
24
Policies can be user-defined or default policies (see below).
Default Policies
Empty default polices exist for each FHS feature and are by default attached to all
VLANs and interfaces. The default policies are named: "vlan_default" and
"port_default" (for each feature):
•
Rules can be added to these default policies. You cannot manually attach
default policies to interfaces. They are attached by default.
•
Default policies can never be deleted. You can only delete the user-added
configuration.
User-Defined Policies
You can define policies other than the default policies.
When a user-defined policy is attached to an interface, the default policy for that
interface is detached. If the user-define policy is detached from the interface, the
default policy is reattached.
Policies do not take effect until:
•
The feature in the policy is enabled on the VLAN containing the interface
•
The policy is attached to the interface (VLAN, port or LAG).
When you attach a policy, the default policy for that interface is detached. When
you remove the policy from the interface, the default policy is reattached.
You can only attach 1 policy (for a specific feature) to a VLAN.
You can attach multiple policies (for a specific feature) to an interface if they
specify different VLANs.
Levels of Verification Rules
The final set of rules that is applied to an input packet on an interface is built in the
following way:
•
The rules configured in policies attached to the interface (port or LAG) on
which the packet arrived are added to the set.