Explains IPv4 and IPv6 first-hop security capabilities and provides guidance for securing address assignment and neighbor-discovery operations through the APIC GUI, CLI, and REST API.
This chapter contains the following sections:
First-hop security
Describes how first-hop security features protect IPv4 and IPv6 address assignment and link operations from unauthorized devices and malicious endpoints on Layer 2 networks.
First-hop security policy deployment
Describes how first-hop security policies define feature behavior, apply to tenant bridge domains or endpoint groups, and resolve overlapping policy assignments.
First-hop security guidelines and limitations
Lists the deployment restrictions, endpoint-binding behavior, traffic effects, and virtual machine manager domain requirements that apply to first-hop security in Cisco ACI.
Configure first-hop security using the Cisco APIC GUI
Configures First-Hop Security and trust control policies in the Cisco APIC GUI and applies them to an endpoint group and bridge domain.
Configure first-hop security using the NX-OS-style CLI
Configures first-hop security and trust control policies using the NX-OS-style CLI, applies the policies, and verifies bindings, violations, and protocol statistics.
Run first-hop security switch iBASH commands
Uses switch commands to inspect first-hop security policies, endpoint bindings, violations, and counters and, when necessary, clear a secured endpoint entry.
Configure first-hop security in Cisco APIC using the REST API
Configures First-Hop Security and trust control policies through the Cisco APIC REST API and applies them to a bridge domain and endpoint group.