Ipv6 Source Guard - Cisco 350XG series Administration Manual

10g stackable managed switches
Table of Contents

Advertisement

Security: IPv6 First Hop Security

IPv6 Source Guard

IPv6 Source Guard
Cisco 350XG & 550XG Series 10G Stackable Managed Switches
To reduce the size of the Neighbor Binding table, NBI-NDP establishes binding
only on perimeterical interfaces (see
distributes binding information through internal interfaces using NS and NA
messages. Before creating an NBI-NDP local binding, the device sends a DAD-NS
message querying for the address involved. If a host replies to that message with
an NA message, the device that sent the DAD-NS message infers that a binding for
that address exists in another device and does not create a local binding for it. If no
NA message is received as a reply to the DAD-NS message, the local device
infers that no binding for that address exists in other devices and creates the local
binding for that address.
NBI-NDP supports a lifetime timer. A value of the timer is configurable in the
Neighbor Binding Settings
IPv6 address is confirmed. If the timer expires, the device sends up to 2 DAD-NS
messages with short intervals to validate the neighbor.
NBI-DHCP Method
The NBI-NDP method is based on the SAVI-DHCP method specified in the SAVI
Solution for DHCP, draft-ietf-savi-dhcp-15, September 11, 2012.
Like NBI-NDP, NBI-DHCP provides perimeterical binding for scalability. The
following difference between the NBI-DHCP and NBI-FCFS method exists: NBI-
DHCP follows the state announced in DHCPv6 messages, thus there is no need to
distribute the state by NS/NA messages.
NB Integrity Policy
In the same way that other IPv6 First Hop Security features function, NB Integrity
behavior on an interface is specified by an NB Integrity policy attached to an
interface. These policies are configured in the
If Neighbor Binding Integrity (NB Integrity) is enabled, IPv6 Source Guard validates
the source IPv6 addresses of NDP and DHCPv6 messages, regardless of whether
IPv6 Source Guard is enabled. If IPv6 Source Guard is enabled together with NB
Integrity, IPv6 Source Guard configures the TCAM to specify which IPv6 data
IPv6 First Hop Security
page. The timer is restarted each time that the bound
Neighbor Binding Settings
24
Perimeter) and
page.
508

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

550xg series

Table of Contents