23
STEP 5
STEP 1
STEP 2
533
-
No Verification—Advertised prefixes are not verified.
-
Match List— IPv6 prefix list to be matched.
•
Match Server Address—Select to enable verification of the DHCP server's
and relay's IPv6 address in received DHCP reply messages within a
DHCPv6 Guard policy.
-
Inherited—Value is inherited from either the VLAN or system default (no
verification).
-
No Verification—Disables verification of the DHCP server's and relay's
IPv6 address.
-
Match List— IPv6 prefix list to be matched.
•
Minimal Preference—See above.
•
Maximal Preference—See above.
Click Apply to add the settings to the Running Configuration file.
To attach this policy to an interface:
•
Attach Policy to VLAN—Click to jump to
where you can attach this policy to a VLAN.
•
Attach Policy to Interface—Click to jump to
page where you can attach this policy to a port.
Neighbor Discovery Inspection Settings
Use the Neighbor Discovery (ND) Inspection Settings page to enable the ND
Inspection feature on a specified group of VLANs and to set the global
configuration values for this feature. If required, a policy can be added or the
system-defined default ND Inspection policies can be configured in this page.
To configure ND Inspection:
Click Security > IPv6 First Hop Security > ND Inspection Settings.
Enter the following global configuration fields:
•
ND Inspection VLAN List—Enter one or more VLANs on which ND
Inspection is enabled.
Security: IPv6 First Hop Security
Configuring IPv6 First Hop Security through Web GUI
Cisco 500 Series Stackable Managed Switch Administration Guide
Policy Attachment (VLAN)
Policy Attachment (Port)
page