EasyManuals Logo

Cisco 500 Series Administration Guide

Cisco 500 Series
653 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #523 background imageLoading...
Page #523 background image
Security: IPv6 First Hop Security
IPv6 Source Guard
521 Cisco 500 Series Stackable Managed Switch Administration Guide
23
IPv6 Source Guard
If Neighbor Binding Integrity (NB Integrity) is enabled, IPv6 Source Guard validates
the source IPv6 addresses of NDP and DHCPv6 messages, regardless of whether
IPv6 Source Guard is enabled. If IPv6 Source Guard is enabled together with NB
Integrity, IPv6 Source Guard configures the TCAM to specify which IPv6 data
frames should be forwarded, dropped, or trapped to the CPU and validates the
source IPv6 addresses of the trapped IPv6 data messages. If NB Integrity is not
enabled, IPv6 Source Guard is not activated regardless of whether it is enabled or
not.
If the TCAM does not have free room to add a new rule, the TCAM overflow
counter is Incremented and a rate-limited SYSLOG message containing the
interface identifier, host MAC address, and host IPv6 address is sent.
IPv6 Source Guard validates the source addresses of all received IPv6 messages
using the Neighbor Binding table except for the following messages that are
passed without validation:
• RS messages, if the source IPv6 address equals the unspecified IPv6
address.
• NS messages, if the source IPv6 address equals the unspecified IPv6
address.
• NA messages, if the source IPv6 address equals the target address.
IPv6 Source Guard drops all other IPv6 messages whose source IPv6 address
equals the unspecified IPv6 address.
IPv6 Source Guard runs only on untrusted interfaces belonging to the perimeter.
IPv6 Source Guard drops an input IPv6 message if:
• The Neighbor Binding table does not contain the IPv6 address
• The Neighbor Binding table contains the IPv6 address, but it is bound to
another interface.
IPv6 Source Guard initiates the Neighbor Recovery process by sending DAD_NS
messages for the unknown source IPv6 addresses.

Table of Contents

Other manuals for Cisco 500 Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco 500 Series and is the answer not in the manual?

Cisco 500 Series Specifications

General IconGeneral
ModelCisco 500 Series
CategorySwitch
MountingRack-mountable
ManagementWeb-based, CLI, SNMP
Ports24, 48
Port Speed10/100/1000 Mbps
PoE SupportAvailable on some models
Switching CapacityUp to 176 Gbps
MAC Address Table Size16, 000 entries
SecurityACLs, 802.1X
Quality of Service (QoS)Yes
DimensionsVaries by model
WeightVaries by model
Humidity10% to 90% non-condensing
Power SupplyInternal
Power ConsumptionVaries by model
Jumbo Frame SupportUp to 9216 bytes

Related product manuals