Security: IPv6 First Hop Security
Configuring IPv6 First Hop Security through Web GUI
529 Cisco 500 Series Stackable Managed Switch Administration Guide
23
• Attach Policy to Interface—Click to jump to Policy Attachment (Port)
page where you can attach this policy to a port.
RA Guard Settings
Use the RA Guard Settings page to enable the RA Guard feature on a specified
group of VLANs and to set the global configuration values for this feature. If
required, a policy can be added or the system-defined default RA Guard policies
can be configured in this page.
To configure RA Guard:
STEP 1 Click Security > IPv6 First Hop Security > RA Guard Settings.
STEP 2 Enter the following global configuration fields:
• RA Guard VLAN List—Enter one or more VLANs on which RA Guard is
enabled.
• Device Role—Displays one of the following options to specify the role of the
device attached to the port for RA Guard.
- Inherited—Role of device is inherited from either the VLAN or system
default (client).
- Router—Role of device is router.
- Host—Role of device is host.
• Minimal Hop Limit—This field indicates whether the RA Guard policy will
check the minimum hop limit of the packet received.
- No Verification—Disables verification of the lower boundary of the hop
count limit.
- User Defined—Verifies that the hop-count limit is greater than or equal
to this value.
• Maximal Hop Limit—This field indicates whether the RA Guard policy will
check the maximum hop limit of the packet received.
- No Verification—Disables verification of the high boundary of the hop-
count limit.