About Vpc First Hop Security Configuration; Dhcp Relay On-Stack - Cisco Nexus 9000 Series Configuration Manual

Nx-os security configuration guide, release 9.x
Hide thumbs Also See for Nexus 9000 Series:
Table of Contents

Advertisement

Configuring IPv6 First Hop Security

About vPC First Hop Security Configuration

You can deploy IPv6 First Hop Security vPC in many ways. We recommend the following best practice
deployment scenarios:

• DHCP relay on-stack

• DHCP relay on vPC leg
• DHCP client and relay on orphan ports
DHCP Relay On-stack
In this deployment scenario, you can directly connect clients behind the vPC link, or behind an intermediary
switch with DHCP relay running on the Nexus switch. Connecting clients behind an intermediary switch with
DHCP relay running on the Nexus switch, is ideal because you can configure the IPv6 Snooping feature on
the vPC interface links directly, instead of at a VLAN level. Configuration at the interface level is efficient
for the following reasons:
• Control traffic (DHCP/ND) will not be redirected to CPU for processing on both vPC peers if it goes
• Packets switched over the peer link aren't processed a second time.
n
over the peer link.
Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 9.x
About vPC First Hop Security Configuration
371

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents