Security: IPv6 First Hop Security
IPv6 First Hop Security Overview
513 Cisco 500 Series Stackable Managed Switch Administration Guide
23
IPv6 First Hop Security Components
IPv6 First Hop Security includes the following features:
• IPv6 First Hop Security Common 
• RA Guard
• ND Inspection
• Neighbor Binding Integrity
• DHCPv6 Guard
• IPv6 Source Guard
These components can be enabled or disabled on VLANs. 
There are two empty, pre-defined policies per each feature with the following 
names: vlan_default and port_default. The first one is attached to each VLAN that 
is not attached to a user-defined policy and the second one is connected to each 
interface and VLAN that is not attached to a user-defined policy. These policies 
cannot be attached explicitly by the user. See Policies, Global Parameters and 
System Defaults.
IPv6 First Hop Security Pipe
If IPv6 First Hop Security is enabled on a VLAN, the switch traps the following 
messages:
• Router Advertisement (RA) messages
• Router Solicitation (RS) messages
NA message Neighbor Advertisement message
NDP Neighbor Discovery Protocol
NS message Neighbor Solicitation message 
RA message Router Advertisement message
RS message Router Solicitation message 
SAVI Source Address Validation Improvement 
Name Description