Security: IPv6 First Hop Security
DHCPv6 Guard
543 Cisco Sx350, SG350X, SG350XG, Sx550X & SG550XG Series Managed Switches, Firmware Release 2.2.5.x
25
Message Validation
ND Inspection validates the Neighbor Discovery protocol messages, based on an ND 
Inspection policy attached to the interface. This policy can be defined in the ND Inspection 
Settings page.
If a message does not pass the verification defined in the policy, it is dropped and a rate limited 
SYSLOG message is sent.
Egress Filtering
ND Inspection blocks forwarding of RS and CPS messages on interfaces configured as host 
interfaces.
DHCPv6 Guard
DHCPv6 Guard treats the trapped DHCPv6 messages. DHCPv6 Guard supports the following 
functions:
• Filtering of received DHCPv6 messages.
DHCP Guard discards DHCPv6 reply messages received on interfaces whose role is 
client. The interface role is configured in the DHCPv6 Guard Settings page.
• Validation of received DHCPv6 messages.
DHCPv6 Guard validates DHCPv6 messages that match the filtering based on the 
DHCPv6 Guard policy attached to the interface. 
If a message does not pass verification, it is dropped. If the logging packet drop configuration 
on the FHS common component is enabled, a rate limited SYSLOG message is sent.
Neighbor Binding Integrity
Neighbor Binding (NB) Integrity establishes binding of neighbors.
A separate, independent instance of NB Integrity runs on each VLAN on which the feature is 
enabled.