![ZyXEL Communications GS2200 Series User Manual Download Page 188](http://html1.mh-extra.com/html/zyxel-communications/gs2200-series/gs2200-series_user-manual_945076188.webp)
Chapter 25 IP Source Guard
GS2200 Series User’s Guide
188
• Use the ARP Inspection Port Configure screen (
) to specify
whether ports are trusted or untrusted ports for ARP inspection.
• Use the ARP Inspection VLAN Configure screen (
) to enable ARP
inspection on each VLAN and to specify when the Switch generates log messages for receiving
ARP packets from each VLAN.
25.1.2 What You Need to Know
The Switch builds the binding table by snooping DHCP packets (dynamic bindings) and from
information provided manually by administrators (static bindings).
IP source guard consists of the following features:
• Static bindings. Use this to create static bindings in the binding table.
• DHCP snooping. Use this to filter unauthorized DHCP packets on the network and to build the
binding table dynamically.
• ARP inspection. Use this to filter unauthorized ARP packets on the network.
If you want to use dynamic bindings to filter unauthorized ARP packets (typical implementation),
you have to enable DHCP snooping before you enable ARP inspection.
25.2 IP Source Guard
Use this screen to look at the current bindings for DHCP snooping and ARP inspection. Bindings are
used by DHCP snooping and ARP inspection to distinguish between authorized and unauthorized
packets in the network. The Switch learns the bindings by snooping DHCP packets (dynamic
bindings) and from information provided manually by administrators (static bindings). To open this
screen, click Advanced Application > IP Source Guard.
Figure 120
IP Source Guard
The following table describes the labels in this screen.
Table 67
IP Source Guard
LABEL
DESCRIPTION
Index
This field displays a sequential number for each binding.
MAC Address
This field displays the source MAC address in the binding.
IP Address
This field displays the IP address assigned to the MAC address in the binding.
Lease
This field displays how many days, hours, minutes, and seconds the binding is valid; for
example, 2d3h4m5s means the binding is still valid for 2 days, 3 hours, 4 minutes, and
5 seconds. This field displays infinity if the binding is always valid (for example, a static
binding).
Summary of Contents for GS2200 Series
Page 15: ...15 PART I User s Guide...
Page 16: ...16...
Page 31: ...31 PART II Technical Reference...
Page 32: ...32...
Page 76: ...Chapter 8 Basic Setting GS2200 Series User s Guide 76...
Page 92: ...Chapter 9 VLAN GS2200 Series User s Guide 92 Figure 60 Port Based VLAN Setup Port Isolation...
Page 230: ...Chapter 29 Error Disable GS2200 Series User s Guide 230...
Page 248: ...Chapter 33 ARP Learning GS2200 Series User s Guide 248...
Page 302: ...Appendix A Changing a Fuse GS2200 Series User s Guide 302...
Page 306: ...Appendix B Common Services GS2200 Series User s Guide 306...
Page 309: ...Appendix C Legal Information GS2200 Series User s Guide 309 ROHS...
Page 310: ...Appendix C Legal Information GS2200 Series User s Guide 310...