
ES-2108 Series User’s Guide
165
C
H A P T E R
2 1
IP Source Guard
Use IP source guard to filter unauthorized ARP packets in your network.
21.1 IP Source Guard Overview
IP source guard uses a binding table to distinguish between authorized and unauthorized ARP
packets in your network. A binding contains these key attributes:
• MAC address
• VLAN ID
• IP address
• Port number
When the Switch receives an ARP packet, it looks up the appropriate MAC address, VLAN
ID, IP address, and port number in the binding table. If there is a binding, the Switch forwards
the packet. If there is not a binding, the Switch discards the packet.
The Switch builds from information provided manually by administrators (static bindings).
IP source guard consists of the following features:
• Static bindings. Use this to create static bindings in the binding table.
• ARP inspection. Use this to filter unauthorized ARP packets on the network.
21.1.1 ARP Inspection Overview
Use ARP inspection to filter unauthorized ARP packets on the network. This can prevent
many kinds of man-in-the-middle attacks, such as the one in the following example.
Figure 90
Example: Man-in-the-middle Attack
A
X
B
Summary of Contents for ES-2108
Page 2: ......
Page 8: ...Safety Warnings ES 2108 Series User s Guide 8...
Page 20: ...Table of Contents ES 2108 Series User s Guide 20...
Page 28: ...List of Tables ES 2108 Series User s Guide 28...
Page 30: ...30...
Page 36: ...Chapter 1 Getting to Know Your Switch ES 2108 Series User s Guide 36...
Page 50: ...50...
Page 60: ...Chapter 4 The Web Configurator ES 2108 Series User s Guide 60...
Page 84: ...Chapter 7 Basic Setting ES 2108 Series User s Guide 84...
Page 86: ...86...
Page 130: ...Chapter 16 Port Authentication ES 2108 Series User s Guide 130...
Page 150: ...Chapter 19 Multicast ES 2108 Series User s Guide 150 Figure 84 MVR Group Configuration Example...
Page 164: ...Chapter 20 Authentication Accounting ES 2108 Series User s Guide 164...
Page 179: ...179 PART IV IP Application Static Route 181 Differentiated Services 185 DHCP 189...
Page 180: ...180...
Page 184: ...Chapter 23 Static Route ES 2108 Series User s Guide 184...
Page 196: ...196...
Page 222: ...Chapter 28 Diagnostic ES 2108 Series User s Guide 222...
Page 226: ...Chapter 29 Syslog ES 2108 Series User s Guide 226...
Page 240: ...240...
Page 248: ...Chapter 34 Troubleshooting ES 2108 Series User s Guide 248...
Page 256: ...Appendix A Product Specifications ES 2108 Series User s Guide 256...
Page 270: ...Appendix C Legal Information ES 2108 Series User s Guide 270...
Page 276: ...Appendix D Customer Support ES 2108 Series User s Guide 276...