Cisco switches that support IPv6 L2 security

I'm looking for Cisco switches that support IPv6 layer 2 security. The following features are required:
MLDv2 snooping [RFC4541]
DHCPv6 snooping [RFC3315]
DHCPv6 messages must be blocked between subscribers and the network so that false DHCPv6 servers cannot distribute addresses.
Router Advertisement (RA) filtering [RFC4862, RFC5006]
RA filtering must be used in the network to block unauthorised RA messages.
Dynamic "IPv6 neighbour solicitation/advertisement" inspection [RFC4862]
There must be an IPv6 neighbour solicitation/advertisement inspection, as in IPv4 "Dynamic ARP Inspection". The table with MAC-address and link-local and other assigned IPv6-addresses must be dynamically created by SLAAC or DHCPv6 messages.
Neighbour Unreachability Detection [NUD, RFC4861] filtering
There must be a NUD filtering function to ensure that false NUD messages cannot be sent.
Duplicate Address Detection [DAD, RFC4429] snooping and filtering
Only authorised addresses may be allowed as source IPv6 addresses in DAD messages from each port.
Source: http://www.ripe.net/ripe/docs/ripe-501
I've looked around in some configuration guides for some Cisco access switches but I can't seem to find any switch supporting these functionalities.

See if this helps.
/* Style Definitions */
table.MsoNormalTable
{mso-style-name:"Table Normal";
mso-tstyle-rowband-size:0;
mso-tstyle-colband-size:0;
mso-style-noshow:yes;
mso-style-priority:99;
mso-style-qformat:yes;
mso-style-parent:"";
mso-padding-alt:0in 5.4pt 0in 5.4pt;
mso-para-margin:0in;
mso-para-margin-bottom:.0001pt;
mso-pagination:widow-orphan;
font-size:10.0pt;
font-family:"Times New Roman","serif";}
http://www.cisco.com/en/US/docs/ios/ipv6/configuration/guide/ip6-roadmap.html
You may also want to consult with your sales team.
What is the application?

Similar Messages

  • Cisco devices that support Multicast traffic?

    Folks,
    I am looking for list of Cisco devices that support Multicast traffic. Does anyone know how to get this information?
    Thanks,
    Nagesh 

    Cisco Feature Navigator

  • Need CISCO switch which support 10 GBPS Traffice

    Hi all,
    In my data center currently I have 13 servers with Cisco Ethernet switch which supports 1 GBPS network that switch is up-linked with a sonicwall firewall.
    We recently bought a new sonicwall firewall which has a two 10GE port.So I am looking now a cisco switch which has at least 16 10GE Fiber ports and one/two 1 GB Ethernet ports.That one  1 GB ports will connect to existing cisco switch and 16 GE FC ports will connect  to firewall and as well as all server which I am planning to move one by one as we buy 10 GB supported SFC Network adapter cards for these servers.
    Can you guys suggest me a Cisco Switch with 10 GE Fiber supported with 1/2 1 GBPS ethernet.Also if you can suggest me 10 GE Supported SFC adapters for Dell R 710,R720 and IBM x3550,M4 and IBMx3650 M4 servers.
    Thank You

    Disclaimer
    The Author of this posting offers the information contained within this posting without consideration and with the reader's understanding that there's no implied or expressed suitability or fitness for any purpose. Information provided is for informational purposes only and should not be construed as rendering professional advice of any kind. Usage of this posting's information is solely at reader's own risk.
    Liability Disclaimer
    In no event shall Author be liable for any damages whatsoever (including, without limitation, damages for loss of use, data or profit) arising out of the use or inability to use the posting's information even if Author has been advised of the possibility of such damage.
    Posting
    4500-X.

  • Cisco switches AVB Support

    Hi,
    Does any one have idea if any Cisco Switch model have (or will have) AVB Feature (Audio Video Bridging) support available ? What switching product have you used for AVB deployments? There should be something from Cisco available now or in near future. 

    AFAIK, Cisco IE4000 (based on 3750X hardware) supports AVB and nothing else today. You may contact Cisco to confirm the availability and roadmaps. The major market is the industrial control facilities. HTH,

  • Need current ethernet switch that supports Appletalk

    I need the name(s) of currently manufactured ethernet switches (4 port or greater) that support Appletalk. Does anyone know if these are available? I use an Etherprint to connect from the ethernet to the HP printer.
    emac G4, 1.25GHz   Mac OS X (10.3.9)   Airport base extreme base, HP 6MP printer

    I agree with Kappy 100%.
    But, I noticed you said you use a Farallon Etherprint adapter?
    If yours is like mine, the etherprint has a special requirement. My etherprint isn't correctly detected by a 10/100 switch, and the switch tries to allow 100BaseT comm to go to the Etherprint. This locks up/locks out the Etherprint. The solution was posted on a Farallon web page (when they existed) 6-7 years ago. You must have a 10baseT hub between any 10/100 switch and the Etherprint - the hub is correctly sensed as 10baseT.
    Like I said, I can't be sure if this applies to you - hope it helps.

  • Cisco platforms that support TTCP

    I would like to test through-put from my routers to a managment station using TTCP. Does anyone know which platforms support TTCP. I am unable to test through-put using TTCP on Cisco 827's.

    According to next document:
    http://www.cisco.com/en/US/tech/tk801/tk36/technologies_tech_note09186a0080094694.shtml
    "TTCP requires Cisco IOS® Software Version 11.2 or higher and Feature Sets IP Plus (is- images) or Service Provider (p- images).
    Note: The ttcp command is a hidden, unsupported, privileged mode command. As such, its availability may vary from one Cisco IOS software release to another, such that it might not exist in some releases. Some platforms, for instance, require the Cisco IOS Enterprise feature set in order to perform this activity."
    HTH

  • Converged 10gig server adapters and Cisco switches

    I have little network with 4 vsphere servers connected to clustered 3750x with 4*1Gig NICs per server.
    Servers are connected to central storage with two 8Gbps FC links per server. I don’t have FO switches cause central storage is equipped with 4 FO ports per controller.
    I want to upgrade servers and central storage. Servers will have two converged 10gig (HP FlexFabric) and 4*1 Gig interfaces
    I need to upgrade 3750x switches with new one with 10 gig interfaces.
    I am looking for two new Cisco switches that can handle converged traffic from server 10gig interfaces (iSCSI, FCoE).
    Nice feature will be if it is possible to connect existing FC storage to the new switches.
    Kind regards,
    Vice Lacmanovic

    Hello, vlacmanov. 
    I recommend at least the Nexus 5000 to support iSCSI and FCoE over your 10GE interface. (http://cs.co/9001SoyL) Do you already have any existing Cisco Nexus on your network?
    Let me know if you have additional concerns or e-mail ([email protected]) me directly. Kind regards. 

  • Non Cisco Switches

    Dear ALL,
    I am an IT Potfessional, Doing Network + . I have a questions:
    1) Do Non Cisco Switches have Access and Trunk ports. What i mean is do non cisco switches distinguish between ethernet prots as trunk and access.
    2) Do we need Cross talk cable for Connectine two non cisco switches preferably D-Link . Also How to interconnect a Cisco switch wioth non cisco switch.
    Regards
    Haseeb

    Disclaimer
    The   Author of this posting offers the information contained within this   posting without consideration and with the reader's understanding that   there's no implied or expressed suitability or fitness for any purpose.   Information provided is for informational purposes only and should not   be construed as rendering professional advice of any kind. Usage of  this  posting's information is solely at reader's own risk.
    Liability Disclaimer
    In   no event shall Author be liable for any damages whatsoever (including,   without limitation, damages for loss of use, data or profit) arising  out  of the use or inability to use the posting's information even if  Author  has been advised of the possibility of such damage.
    Posting
    As Daniel noted "decent" switches, i.e. manageable and supporting VLANs, will generally support VLAN tagging ports using the 801.2q standard.  (NB: this standard allows VLAN tagging between different vendors.)  Switches that support VLANs will distinguish between untagged (edge) ports (e.g. Cisco access) and the tagged ports (e.g. a Cisco trunk), but as Daniel also noted, their terminology might be different.
    As Leo noted, many switches offer auto MDI/MDI-X.  Surprisingly, this feature was often seen on unmanageable switches before it was seen on manageable switches.  Also on older unmanageable switches, you might find a pair of physical ports that are the same logical port, one wired MDI and other wired MDI-X or you might find some button to change one port's MDI to/from MDI-X.  Such "special" ports are often the "uplink" port.  (NB: the purpose of the "uplink" port was to allow connecting it to another switch whether you had a straight through or cross over cable.)
    If you do have a switch supporting auto MDI/MDI-X, or one with the earlier physical MDI/MDI-X options, you only need one switch, not both with such a feature, to support either a straight through or cross over cable.  Of course, both switches might have such an option, which is fine too.  Only if both switches are "hard wired", you'll need a cross over cable for a switch to switch connection.

  • How will the Time Capsule support IPv6 and coop with the new emerging security threats that will emerge due to the new technical possibilities that IPv6 provide?

    How will the Time Capsule support IPv6 and coop with the new emerging security threats that will emerge due to the new technical possibilities that IPv6 provide?

    Cross your fingers and hope.
    Obviously if there is any big or known threat Apple will send out a firmware fix.
    But the TC is designed to be end user simple device. It has no firewall that is visible at any rate. I don't know that it truly doesn't have a firewall but it is not part of the end user controls.
    IMO if you have major security concerns that go beyond end device firewall, which is where Apple do put most of the security, since firewall in the router is plainly not a stop to anybody deliberately downloading an infected file or website, and most end users.. do not want a firewall that prevents them using the web like a business does, where only certain ports are allowed. Everything else tough luck.. you are not allowed to use it. Then TC is unsuitable for you anyway.. buy a proper firewall appliance.

  • Does Cisco Cloud E-mail Security Solution Support IPv6?

    For the Cisco Cloud E-mail Security Solution - does it support both inbound and outbound IPv6?  Are there any limitations?  I know the IronPort E-mail Security Appliances supports IPv6 - but specifically interested in the cloud service.
    Thanks,
    --Jim

    arkhane wrote:
    Hi.
    Does anyone could explain me about SSL/TLS?
    Here is the situation:
    E72 allows in securîty settings to select SSL/TLS. I selected it for both accessing and sending mails and I can logon to my POP and send with SMTP.  So apparently no problem.
    But I asked my internet provider if they support SSL/TLS and they told me no they does not support it....so my question is does really SSL/TLS works in my situation and my provider has no clue on security settings or SSL/TLS does not work but it has no incidence on using my mails as I said I can receive mails and send mails even if those security settings are selected...?
    Thanks if anyone could explain me this.
    Some e-mail providers like Gmail use SSL/TLS.
    http://mail.google.com/support/bin/answer.py?answer=13287
    ‡Thank you for hitting the Blue/Green Star button‡
    N8-00 RM 596 V:111.030.0609; E71-1(05) RM 346 V: 500.21.009

  • Physical port security on Cisco switching

    We have a security problem I would like to resolve. Like most sites our wired network has live ports that periodically, non corporate PCs and laptops connect up to without our knowledge. In our network we do not filter for valid MAC addresses although Ive learned this is a poor approach to security as MAC can be changed in about 10 seconds.
    I would like a solution that would validate corporate systems and let them through the Cisco layer 3 switching and block out all other devices which attempt connection. We do not currently have IDS or IPS and are not likely to in short term.
    Is there a hardware or software or combination solution out there that works well for this ?
    Thank you

    Steve
    2 solutions spring to mind
    1) 802.1x authentication. Microsoft XP/Vista has built in 802.1x supplicant and Cisco switches support Network EAP used to pass the 802.1x messages. What you also need is an authentication server such as Cisco Secure ACS server although Microsoft IAS server also supports 802.1x.
    Basically before a client is allowed access to the network they have to authenticate to the network with valid credentials otherwise the port is shutdown.
    2) NAC - Network Admission Control. This goes one step further than 1) whereby the client is also checked to see if it conforms to company policy eg. does it have the right virus checker on it etc.. and if it doesn't the client can be quarantined.
    A search on Cisco's website for both NAC and 802.1x will provide a lot of useful links.
    Jon

  • A rugged switch that can support PoE+ on 4 ports

    We are mounting 4 Access points in a parking Lott. We have wired up a cat6 cable to each AP (not power). The cat6 cables are terminated in a weather resistant outdoor box.
    My question is: Does Cisco have at rouged switch that can support this setup?
    The plan was to use a IE2000. However the IE-2000-16PTC-G-L that we purchased, did not deliver enough power on each port (it can deliver PoE on 4 ports, but only PoE+ on 2) My fault that I did not read the PDF thoroughly enough :-( 
    So question is, does cisco have a rugged switch that can deliver PoE+ on 4 ports?

    I believe you'd have to move up to the IE3000 series with the 8-port module (Cisco IEM-3000-4PC-4TC=). That module will deliver POE+ on 4 of its 8 ports. Reference.

  • Which CISCO switch supports SFP, SFP+ and 10G ethernet ports

    I would like to have information about a CISCO switch which can support fiber ports SFP(1g) and SFP+(10g) and copper 1g and 10g ethernet ports. And will it also software upgradable to support L3 protocols ?

    You can choose from the Cisco 3560-E, 4900, 4500, and 6500 series switches. That's in order of capability (and cost!), from least to greatest.
    The 3560-E and 4900 series are fixed chassis systems (the 4900M is semi-modular) while the 4500 and 6500 series are completely modular - buy the chassis and populate it according to your requirements.
    In addition to the references cited above, also refer to the Cisco Products Quick Reference Guide (CPQRG), available at http://www.cisco.com/en/US/prod/qrg/index.html
    Hope this helps. Please rate this post if it does.

  • How do I switch to 'fly by' view in iOS 6 Maps in cities that support it?

    Curious how to switch to this fly by mode in cities that support it in the new Maps app.
    Thanks
    Harry

    Add your own review to those already there complaining about this:
    https://itunes.apple.com/us/book/big-nate-makes-a-splash/id651440000?mt=11
    You could also try asking for a refund via the "report a problem" link on your receipt.

  • SP324081: Check that your Internet Explorer security settings will allow JavaScript and cookies. If enabled, please contact support.

    Hi,
    I have VS2013 update 4 and IE11 installed. When I try to sign in through VS I get the following error.
    SP324081: Check that your Internet Explorer security settings will allow JavaScript and cookies. If enabled, please contact support.
    I have checked and JAVASCRIPT and cookies are enabled.
    Any help is appreciated.

    Hi Sath12,
    If possible, I suggest you reset IE settings.
    Please lower the security level. Then I added the site like https://*.visualstudio.com/ to the trusted zones. Test it again.
    I have met this issue before which was related to the IE settings or the account issue.
    https://social.msdn.microsoft.com/Forums/sqlserver/en-US/290948f6-b4ca-41e3-9888-91fbbc71cdeb/cannot-register-sign-in-from-vs-express-2013?forum=visualstudiogeneral
    A connect report still shared some information about it:
    https://connect.microsoft.com/VisualStudio/feedback/details/811860/vs-express-2013-for-web-browser-is-security-restricted-or-javascript-is-disabled
    Best Regards,
    Jack
    We are trying to better understand customer views on social support experience, so your participation in this interview project would be greatly appreciated if you have time. Thanks for helping make community forums a great place.
    Click
    HERE to participate the survey.

Maybe you are looking for