
IndexIndex
attack, where high numbers of TCP SYN messages are sent towards a host in
order to drain its execution capacity, is an example of attack that may be
stopped. IP source address filtering immediately stops packets with false IP
source addresses.
The EFN324 gets information about valid IP addresses in two ways. Static IP
addresses can be configured for each Enduser by the operator. Alternatively,
the EFN324 learns IP addresses dynamically by DHCP snooping. The two
methods do not exclude each other, since it is possible to simultaneously have
both static and dynamic addresses for an Enduser.
8.2.1
Configuration of IP Validation
Set ‘switching_rule’ to ‘ip_validation’ in ‘vlan’. Also set an ‘uplink’ and optionally
a ‘gateway’
.
Valid IP addresses may be ‘static’ or ‘dynamic’. Static addresses are added to,
or removed from, the connection object using
add
and
remove
commands. For
example:
#
add connection vlan 1 ethernet_port 1 static_ip_addresses
<
IPv4ADDRESS>
Dynamic addresses are learned by the EFN324 by snooping DHCP ACK
messages on their way from the DHCP server to the Enduser. It is possible to
set a maximum number of dynamically learned IP addresses that can be set
and saved per switching domain and Enduser port.
Both static and learnt IP addresses may be read out from each connection
object.
Setting max_dynamic_ip_addresses to zero means that dynamic IP addresses
are not allowed. In that case static IP addresses must be defined. Note that
static IP addresses may be defined even though dynamic IP addresses are
allowed.
8.2.2
IP Validation to Host Port
IP validation, and other forced forwarding mechanisms, are primarily intended
for use on Enduser connections. IP validation may also be applied on
connections to the host port. This is, however, unnecessary. The host is an
internal system function and must be considered ‘safe’. In addition, the use of
a Management VLAN, see section 10.3 on page 79, eliminates the need for
extra forced forwarding security mechanisms.
Summary of Contents for EFN324
Page 1: ...EFN324 User Guide EDA 1200...
Page 4: ...Error No text of specified style in document Glossary 168 Index 170...
Page 176: ......