Security: IPV6 First Hop Security
First Hop Security Overview
412 Cisco Small Business 200, 300 and 500 Series Managed Switch Administration Guide (Internal Version)
20
IPv6 First Hop Security Components
IPv6 First Hop Security includes the following features:
IPv6 First Hop Security Common
RA Guard
ND Inspection
Neighbor Binding Integrity
DHCPv6 Guard
These components can be enabled or disabled on VLANs.
There are two empty, pre-defined policies per each feature with the following
names: vlan_default and port_default. The first one is attached to each VLAN that
is not attached to a user-defined policy and the second one is connected to each
interface and VLAN that is not attached to a user-defined policy. These policies
cannot be attached explicitly by the user. See Policies, Global Parameters and
System Defaults.

IPv6 First Hop Security Pipe

If IPv6 First Hop Security is enabled on a VLAN, the switch traps the following
messages:
Router Advertisement (RA) messages
Router Solicitation (RS) messages
Neighbor Advertisement (NA) messages
NA message Neighbor Advertisement message
NDP Neighbor Discovery Protocol
NS message Neighbor Solicitation message
RA message Router Advertisement message
RS message Router Solicitation message
SAVI Source Address Validation Improvement
Name Description