![Cisco 350XG series Скачать руководство пользователя страница 543](http://html.mh-extra.com/html/cisco/350xg-series/350xg-series_administration-manual_67491543.webp)
Security: IPv6 First Hop Security
Configuring IPv6 First Hop Security through Web GUI
Cisco 350XG & 550XG Series 10G Stackable Managed Switches
524
24
To configure ND Inspection:
STEP 1
Click
Security
>
IPv6 First Hop Security
>
ND Inspection Settings
.
STEP 2
Enter the following global configuration fields:
•
ND Inspection VLAN List
—Enter one or more VLANs on which ND
Inspection is enabled.
•
Device Role
—Displays the device role that is explained below.
•
Drop Unsecure
—Select to enable dropping messages with no CGA or RSA
Signature option within an IPv6 ND Inspection policy.
•
Minimal Security Level
—If unsecure messages are not dropped, select the
security level below which messages are not forwarded.
-
No Verification
—Disables verification of the security level.
-
User Defined
—Specify the security level of the message to be
forwarded.
•
Validate Source MAC
—Select to globally enable checking source MAC
address against the link-layer address:
STEP 3
If required, click
Add
to create an ND Inspection policy.
STEP 4
Enter the following fields:
•
Policy Name
—Enter a user-defined policy name.
•
Device Role
—Select either
Server
or
Client
to specify the role of the device
attached to the port for ND Inspection.
-
Inherited
—Role of device is inherited from either the VLAN or system
default (client).
-
Host
—Role of device is host.
-
Router
—Role of device is router.
•
Drop Unsecure
—Select one of following options:
-
Inherited
—Inherit value from VLAN or system default (disabled).
-
Enable
—Enable dropping messages with no CGA or RSA Signature
option within an IPv6 ND Inspection policy.
-
Disable
—Disable dropping messages with no CGA or RSA Signature
option within an IPv6 ND Inspection policy.