
Glossary
forwarding mechanisms utilize the MAC address. The IP address is
only needed as a means to, through ARP, retrieve the MAC address.
2. In the form of an
IP address
. For this option, the EFN324 must send
an ARP to retrieve the gateway MAC address. This is described in
more detail below.
3. As
auto
. For this option, the gateway IP address is snooped from the
DHCP ACK message directed to the Enduser who first issued a DHCP
request. After this, the gateway MAC address is retrieved in the same
way as in option 2.
If, in option 3, all downlink messages in the access network originated from the
gateway, the gateway MAC address could be retrieved from any downlink
message. However, this may not always be the case. The DHCP traffic may
enter the access network elsewhere. Therefore the gateway MAC address
must be retrieved using ARP.
The switching domain resource attributes ‘ip_address’ and ‘mac_address’ are
introduced as an option, so that the operator can provide the EFN324 with the
switching domain specific address to be used as sender in the ARP request.
By default, these attributes are ‘auto’. At ‘auto’ the IP or MAC address is
snooped from the first available ARP, IGMP or DHCP message from a client,
and ‘borrowed’ for use in the own ARP request.
The attributes borrowed_ip_address and borrowed_mac_address (in the
switching domain resource) are status information about the sender source
addresses that the EFN324 uses in ARP requests.
8.2
IP Validation
Another security measure is IP validation. That means that IP addresses are
also checked during forwarding decisions for unicast packets. Multicast and
broadcast are treated according to special rules.
Note:
This feature can only be used if forced forwarding is activated.
Enduser IP addresses are validated per port. That is, only upstream packets
with the Enduser IP source addresses and downstream packets with End
user address as destination addresses are let through. All other packets are
discarded.
IP source address validation, also called IP source address filtering, aims to
stop malicious Endusers from sabotaging the network. The socalled SYN
Summary of Contents for EFN324
Page 1: ...EFN324 User Guide EDA 1200...
Page 4: ...Error No text of specified style in document Glossary 168 Index 170...
Page 176: ......