![HP HP ProCurve Series 6600 Access Security Manual Download Page 576](http://html.mh-extra.com/html/hp/hp-procurve-series-6600/hp-procurve-series-6600_access-security-manual_163101576.webp)
11-26
Configuring Advanced Threat Protection
Dynamic IP Lockdown
Assuming that DHCP snooping is enabled and that port 5 is untrusted,
dynamic IP lockdown applies the following dynamic VLAN filtering on port 5:
Figure 11-4. Example of Internal Statements used by Dynamic IP Lockdown
Note that the
deny any
statement is applied only to VLANs for which DHCP
snooping is enabled. The
permit any
statement is applied only to all other
VLANs.
Enabling Dynamic IP Lockdown
To enable dynamic IP lockdown on all ports or specified ports, enter the
ip
source-lockdown
command at the global configuration level. Use the
no
form of the command to disable dynamic IP lockdown.
Operating Notes
■
Dynamic IP lockdown is enabled at the port configuration level and
applies to all bridged or routed IP packets entering the switch. The only
IP packets that are exempt from dynamic IP lockdown are broadcast
DHCP request packets, which are handled by DHCP snooping.
■
DHCP snooping is a prerequisite for Dynamic IP Lockdown operation.
The following restrictions apply:
•
DHCP snooping is required for dynamic IP lockdown to operate. To
enable DHCP snooping, enter the
dhcp-snooping
command at the
global configuration level.
Syntax:
[no] ip source-lockdown <
port-list
>
Enables dynamic IP lockdown globally on all ports or on
specified ports on the routing switch.
permit 10.0.8.5 001122-334455 vlan 2
permit 10.0.8.7 001122-334477 vlan 2
permit 10.0.10.3 001122-334433 vlan 5
deny any vlan 1-10
permit any
permit 10.0.10.1 001122-110011 vlan 5
Summary of Contents for HP ProCurve Series 6600
Page 2: ......
Page 6: ...iv ...
Page 26: ...xxiv ...
Page 102: ...2 48 Configuring Username and Password Security Password Recovery ...
Page 204: ...4 72 Web and MAC Authentication Client Status ...
Page 550: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 612: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 734: ...14 44 Configuring and Monitoring Port Security Operating Notes for Port Security ...
Page 756: ...16 8 Key Management System Configuring Key Chain Management ...
Page 776: ...20 Index web server proxy 14 42 webagent access 6 6 wildcard See ACL wildcard See ACL ...
Page 777: ......