GS2200 Series User’s Guide
187
C
H A P T E R
2 5
IP Source Guard
25.1 Overview
Use IP source guard to filter unauthorized DHCP and ARP packets in your network.
IP source guard uses a binding table to distinguish between authorized and unauthorized DHCP and
ARP packets in your network. A binding contains these key attributes:
• MAC address
• VLAN ID
• IP address
• Port number
When the Switch receives a DHCP or ARP packet, it looks up the appropriate MAC address, VLAN ID,
IP address, and port number in the binding table. If there is a binding, the Switch forwards the
packet. If there is not a binding, the Switch discards the packet.
25.1.1 What You Can Do
• Use the IP Source Guard screen (
) to look at the current bindings for
DHCP snooping and ARP inspection.
• Use the IP Source Guard Static Binding screen (
) to manage static
bindings for DHCP snooping and ARP inspection.
• Use the DHCP Snooping screen (
) to look at various statistics about
the DHCP snooping database.
• Use this DHCP Snooping Configure screen (
) to enable DHCP
snooping on the Switch (not on specific VLAN), specify the VLAN where the default DHCP server
is located, and configure the DHCP snooping database.
• Use the DHCP Snooping Port Configure screen (
) to specify
whether ports are trusted or untrusted ports for DHCP snooping.
• Use the DHCP Snooping VLAN Configure screen (
) to enable DHCP
snooping on each VLAN and to specify whether or not the Switch adds DHCP relay agent option
82 information to DHCP requests that the Switch relays to a DHCP server for each VLAN.
• Use the ARP Inspection Status screen (
) to look at the current list of
MAC address filters that were created because the Switch identified an unauthorized ARP packet.
• Use the ARP Inspection VLAN Status screen (
) to look at various
statistics about ARP packets in each VLAN.
• Use the ARP Inspection Log Status screen (
) to look at log messages
that were generated by ARP packets and that have not been sent to the syslog server yet.
• Use the ARP Inspection Configure screen (
) to enable ARP inspection
on the Switch. You can also configure the length of time the Switch stores records of discarded
ARP packets and global settings for the ARP inspection log.
Summary of Contents for GS2200 Series
Page 15: ...15 PART I User s Guide...
Page 16: ...16...
Page 31: ...31 PART II Technical Reference...
Page 32: ...32...
Page 76: ...Chapter 8 Basic Setting GS2200 Series User s Guide 76...
Page 92: ...Chapter 9 VLAN GS2200 Series User s Guide 92 Figure 60 Port Based VLAN Setup Port Isolation...
Page 230: ...Chapter 29 Error Disable GS2200 Series User s Guide 230...
Page 248: ...Chapter 33 ARP Learning GS2200 Series User s Guide 248...
Page 302: ...Appendix A Changing a Fuse GS2200 Series User s Guide 302...
Page 306: ...Appendix B Common Services GS2200 Series User s Guide 306...
Page 309: ...Appendix C Legal Information GS2200 Series User s Guide 309 ROHS...
Page 310: ...Appendix C Legal Information GS2200 Series User s Guide 310...