![Dell PowerConnect M6220 User Configuration Manual Download Page 785](http://html.mh-extra.com/html/dell/powerconnect-m6220/powerconnect-m6220_user-configuration-manual_84547785.webp)
Snooping and Inspecting Traffic
785
What Is IP Source Guard?
IPSG is a security feature that filters IP packets based on source ID. This
feature helps protect the network from attacks that use IP address spoofing to
compromise or overwhelm the network.
The source ID may be either the source IP address or a {source IP address,
source MAC address} pair. You can configure:
• Whether enforcement includes the source MAC address
• Static authorized source IDs
The DHCP snooping bindings database and static IPSG entries identify
authorized source IDs. IPSG can be enabled on physical and LAG ports.
If you enable IPSG on a port where DHCP snooping is disabled or where
DHCP snooping is enabled but the port is trusted, all IP traffic received on
that port is dropped depending on the admin-configured IPSG entries.
IPSG and Port Security
IPSG interacts with port security, also known as port MAC locking, (see "Port
Security (Port-MAC Locking)" on page 518) to enforce the source MAC
address. Port security controls source MAC address learning in the layer 2
forwarding database (MAC address table). When a frame is received with a
previously unlearned source MAC address, port security queries the IPSG
feature to determine whether the MAC address belongs to a valid binding.
If IPSG is disabled on the ingress port, IPSG replies that the MAC is valid. If
IPSG is enabled on the ingress port, IPSG checks the bindings database. If
the MAC address is in the bindings database and the binding matches the
VLAN the frame was received on, IPSG replies that the MAC is valid. If the
MAC is not in the bindings database, IPSG informs port security that the
frame is a security violation.
In the case of an IPSG violation, port security takes whatever action it
normally takes upon receipt of an unauthorized frame. Port security limits the
number of MAC addresses to a configured maximum. If the limit
n
is less
than the number of stations
m
in the bindings database, port security allows
only
n
stations to use the port. If
n > m
, port security allows only the stations
in the bindings database. For information about configuring the Port Security
feature, see "Configuring Port and System Security" on page 481.
Summary of Contents for PowerConnect M6220
Page 52: ...52 Introduction ...
Page 86: ...86 Switch Features ...
Page 100: ...100 Hardware Overview ...
Page 116: ...116 Using the Command Line Interface ...
Page 121: ...Default Settings 121 ...
Page 122: ...122 Default Settings ...
Page 142: ...142 Setting Basic Network Information ...
Page 206: ...206 Configuring Authentication Authorization and Accounting ...
Page 292: ...292 Managing General System Settings Figure 11 31 Verify MOTD ...
Page 296: ...296 Managing General System Settings ...
Page 332: ...332 Configuring SNMP ...
Page 408: ...408 Monitoring Switch Traffic ...
Page 560: ...560 Configuring Access Control Lists ...
Page 591: ...Configuring VLANs 591 Figure 21 17 GVRP Port Parameters Table ...
Page 597: ...Configuring VLANs 597 Figure 21 24 Double VLAN Port Parameter Table ...
Page 693: ...Configuring Port Based Traffic Control 693 Figure 24 3 Storm Control 5 Click Apply ...
Page 780: ...780 Configuring Connectivity Fault Management ...
Page 804: ...804 Snooping and Inspecting Traffic Figure 27 17 DAI Interface Configuration Summary ...
Page 818: ...818 Snooping and Inspecting Traffic ...
Page 836: ...836 Configuring Link Aggregation ...
Page 860: ...860 Configuring Data Center Bridging Features ...
Page 906: ...906 Configuring DHCP Server Settings ...
Page 940: ...940 Configuring L2 and L3 Relay Features Figure 34 3 DHCP Relay Interface Summary ...
Page 1080: ...1080 Configuring VRRP ...
Page 1104: ...1104 Configuring IPv6 Routing ...
Page 1131: ...Configuring Differentiated Services 1131 Figure 40 5 DiffServ Class Criteria ...
Page 1158: ...1158 Configuring Class of Service Figure 41 1 Mapping Table Configuration CoS 802 1P ...
Page 1174: ...1174 Configuring Auto VoIP Figure 42 2 Auto VoIP Interface Configuration ...
Page 1240: ...1240 Managing IPv4 and IPv6 Multicast Figure 43 51 DVMRP Next Hop Summary ...
Page 1266: ...1266 Managing IPv4 and IPv6 Multicast ...
Page 1274: ...1274 System Process Definitions ...
Page 1294: ...1294 Index ...