
105
manually configured entries in the IP Source Guard table, or dynamic entries in the DHCP
Snooping table when enabled (see "Configuring DHCP Snooping"). IP source guard can be
used to prevent traffic attacks caused when a host tries to use the IP address of a neighbor
to access the network.
Configuring Global Mode and Port Settings for IP Source Guard
Use the IP Source Guard Configuration page to filter traffic on an insecure port which
receives messages from outside the network or fire wall, and therefore may be subject to
traffic attacks caused by a host trying to use the IP address of a neighbor. IP Source Guard
filters traffic type based on the source IP address and MAC address pairs found in the DHCP
Snooping table, or based upon static entries configured in the IP Source Guard Table.
PATH
Configuration \ Security \ Network \ IP Source Guard \ Configuration
Figure 37: Configuring IP Source Guard
COMMAND USAGE
◆
When IP Source Guard is enabled globally and on a port, the switch checks the VLAN ID,
source IP address, and port number against all entries in the DHCP Snooping binding
table and IP Source Guard Static Table. If no matching entry is found, the packet is
dropped. NOTE: Multicast addresses cannot be used by IP Source Guard.
◆
When enabled, traffic is filtered based upon dynamic entries learned via DHCP snooping
(see "Configuring DHCP Snooping"), or static addresses configured in the source guard
binding table.
◆
If IP source guard is enabled, an inbound packet’s IP address will be checked against the
Summary of Contents for GEP-1070
Page 80: ...80 authentication from any point within the network...
Page 168: ...168...