Security: IPv6 First Hop Security
Configuring IPv6 First Hop Security through Web GUI
Cisco 350, 350X and 550X Series Managed Switches, Firmware Release 2.4, ver 0.4 458
26
- Inherited—Device role is inherited from either the VLAN or system default (client).
- Host—Device role is host.
- Router—Device role is router.
• Managed Configuration Flag—This field specifies verification of the advertised
Managed Address Configuration flag within an IPv6 RA Guard policy.
- Inherited—Feature is inherited from either the VLAN or system default (client).
- No Verification—Disables verification of the advertised Managed Address
Configuration flag.
- On—Enables verification of the advertised Managed Address Configuration flag.
- Off—The value of the flag must be 0.
• Other Configuration Flag—This field specifies verification of the advertised Other
Configuration flag within an IPv6 RA Guard policy.
- Inherited—Feature is inherited from either the VLAN or system default (client).
- No Verification—Disables verification of the advertised Other Configuration flag.
- On—Enables verification of the advertised Managed Other flag.
- Off—The value of the flag must be 0.
• RA Address List—Specify the list of addresses to filter:
- Inherited—Value is inherited from either the VLAN or system default (no
verification).
- No Verification—Advertised addresses are not verified.
- Match List— IPv6 address list to be matched.
• RA Prefix List—Specify the list of addresses to filter:
- Inherited—Value is inherited from either the VLAN or system default (no
verification).
- No Verification—Advertised prefixes are not verified.
- Match List— Prefix list to be matched.
• Minimal Hop Limit—Indicates if the RA Guard policy checks the minimum hop limit
of the packet received.
- Inherited—Feature is inherited from either the VLAN or system default (client).