EasyManuals Logo

Cisco SF350-24P Administration Guide

Cisco SF350-24P
762 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #591 background imageLoading...
Page #591 background image
Security: IPv6 First Hop Security
Attack Protection
Cisco 350, 350X and 550X Series Managed Switches, Firmware Release 2.4, ver 0.4 450
26
NA messages, if the source IPv6 address equals the target address.
IPv6 Source Guard drops all other IPv6 messages whose source IPv6 address equals the
unspecified IPv6 address.
IPv6 Source Guard runs only on untrusted interfaces belonging to the perimeter.
IPv6 Source Guard drops an input IPv6 message if:
The Neighbor Binding table does not contain the IPv6 address
The Neighbor Binding table contains the IPv6 address, but it is bound to another
interface.
IPv6 Source Guard initiates the Neighbor Recovery process by sending DAD_NS messages
for the unknown source IPv6 addresses.
Attack Protection
The section describes attack protection provided by IPv6 First Hop Security
Protection against IPv6 Router Spoofing
An IPv6 host can use the received RA messages for:
IPv6 router discovery
Stateless address configuration
A malicious host could send RA messages advertising itself as an IPv6 router and providing
counterfeit prefixes for stateless address configuration.
RA Guard provides protection against such attacks by configuring the interface role as a host
interface for all interfaces where IPv6 routers cannot be connected.
Protection against IPv6 Address Resolution Spoofing
A malicious host could send NA messages advertising itself as an IPv6 Host having the given
IPv6 address.
NB Integrity provides protection against such attacks in the following ways:
If the given IPv6 address is unknown, the Neighbor Solicitation (NS) message is
forwarded only on inner interfaces.

Table of Contents

Other manuals for Cisco SF350-24P

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco SF350-24P and is the answer not in the manual?

Cisco SF350-24P Specifications

General IconGeneral
ModelSF350-24P
CategorySwitch
PoE Budget195W
LayerLayer 3
Power SupplyInternal
Uplink Ports2 x combo Gigabit SFP + 2 x Gigabit
MAC Address Table Size16K entries
Jumbo Frame Support9216 bytes
ManagementWeb, CLI, SNMP
FeaturesQoS, VLAN, IPv6, ACLs
Dimensions440 mm x 257 mm x 44 mm
Operating Temperature0°C to 45°C
Operating Humidity10% to 90% non-condensing
Weight3.48 kg

Related product manuals