EasyManuals Logo

Cisco SG350-10MP Administration Guide

Cisco SG350-10MP
762 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #591 background imageLoading...
Page #591 background image
Security: IPv6 First Hop Security
Attack Protection
Cisco 350, 350X and 550X Series Managed Switches, Firmware Release 2.4, ver 0.4 450
26
NA messages, if the source IPv6 address equals the target address.
IPv6 Source Guard drops all other IPv6 messages whose source IPv6 address equals the
unspecified IPv6 address.
IPv6 Source Guard runs only on untrusted interfaces belonging to the perimeter.
IPv6 Source Guard drops an input IPv6 message if:
The Neighbor Binding table does not contain the IPv6 address
The Neighbor Binding table contains the IPv6 address, but it is bound to another
interface.
IPv6 Source Guard initiates the Neighbor Recovery process by sending DAD_NS messages
for the unknown source IPv6 addresses.
Attack Protection
The section describes attack protection provided by IPv6 First Hop Security
Protection against IPv6 Router Spoofing
An IPv6 host can use the received RA messages for:
IPv6 router discovery
Stateless address configuration
A malicious host could send RA messages advertising itself as an IPv6 router and providing
counterfeit prefixes for stateless address configuration.
RA Guard provides protection against such attacks by configuring the interface role as a host
interface for all interfaces where IPv6 routers cannot be connected.
Protection against IPv6 Address Resolution Spoofing
A malicious host could send NA messages advertising itself as an IPv6 Host having the given
IPv6 address.
NB Integrity provides protection against such attacks in the following ways:
If the given IPv6 address is unknown, the Neighbor Solicitation (NS) message is
forwarded only on inner interfaces.

Table of Contents

Other manuals for Cisco SG350-10MP

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco SG350-10MP and is the answer not in the manual?

Cisco SG350-10MP Specifications

General IconGeneral
ModelSG350-10MP
CategorySwitch
PoE Budget130W
Switching Capacity20 Gbps
Forwarding Rate14.88 Mpps
Power SupplyInternal
Ports8 x 10/100/1000 PoE+ + 2 x Gigabit SFP
MAC Address Table Size16K
Jumbo Frame Support9216 bytes
ManagementWeb-based, CLI, SNMP
Operating Temperature0°C to 45°C (32°F to 113°F)
Storage Temperature-20°C to 70°C (-4°F to 158°F)
Operating Humidity10% to 90% relative humidity, non-condensing
Storage Humidity5% to 95% relative humidity, non-condensing
Dimensions (W x D x H)279.4 x 170 x 44 mm (11.0 x 6.7 x 1.73 in)

Related product manuals