Figure 12: FHS Configuration with DHCP relay on-stack
In the figure, snooping policy is enabled on both vPC links. In this scenario, the two vPC peers learn all the
host IP/MAC bindings behind the vPC links and sync these up between themselves. The two vPC peers learn
the bindings using both IPv6 ND and IPv6 DHCP control protocols.
DHCP Relay on VPC Leg
In this configuration, the relay agent does not run on the vPC peers. Instead, the DHCP relay agent (or a DHCP
server) is runs behind a vPC link (it can be towards the access, or even somewhere in the core). In such a
deployment scenario, the IPv6 Snooping feature doesn’t implicitly trust the DHCP Server messages and drops
DHCP Server messages by default. You can customize the IPv6 policy to implement:
• Security-level glean.
• IPv6 DHCP Guard policy with device-role server. In this configuration, IPv6 Snooping trusts DHCP
server messages attached to the vPC link.
Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 9.x
372
Configuring IPv6 First Hop Security
DHCP Relay on VPC Leg