Chapter 26 IP Source Guard
GS2210 Series User’s Guide
244
26.11 IPv6 Source Guard Overview
The pur pose of I Pv6 sour ce guar d is t o dist inguish bet w een aut hor ized and unaut hor ized user s by
using a binding t able t hat validat es t he sour ce of I Pv6 t raffic. The binding t able can be m anually
cr eat ed or be lear ned t hr ough Dynam ic Host Configurat ion Prot ocol ver sion 6 snooping ( DHCPv6
snooping) . I Pv6 sour ce guar d can deny I Pv6 t raffic fr om an unknow n sour ce. The I Pv6 sour ce guar d
binding t able includes:
•
I Pv6 addr ess
•
I Pv6 pr efix
•
VLAN I D
•
Por t num ber
•
MAC address
Enable I Pv6 sour ce guar d on a por t for t he Sw it ch t o check incom ing I Pv6 packet s on t hat por t . A
packet is allow ed w hen it m at ches any ent r y in t he I PSG binding t able. I f a user t r ies t o send I Pv6
packet s t o t he Swit ch t hat do not m at ch an ent r y in t he I PSG binding t able, t he Sw it ch w ill dr op
t hese packet s. The Sw it ch for war ds m at ching t raffic nor m ally.
26.12 IPv6 Source Binding Status
Use t his scr een t o look at t he cur r ent I Pv6 dynam ic and st at ic bindings and t o r em ove dynam ic
bindings based on I Pv6 addr ess and/ or I Pv6 pr efix. Bindings ar e used t o dist inguish bet w een
aut hor ized and unaut hor ized packet s in t he net w or k. The Sw it ch lear ns t he bindings by snooping
DHCP packet s ( dynam ic bindings) and fr om infor m at ion pr ov ided m anually by adm inist rat or s ( st at ic
bindings) . To open t his scr een, click Adv a n ce d Applica t ion > I P Sou r ce Gu a r d > I Pv 6 Sou r ce
Bin din g St a t u s.
Log
Specify w hen t he Sw it ch generat es log m essages for r eceiving ARP packet s from t he
VLAN.
N on e : The Sw it ch does not generat e any log m essages w hen it r eceives an ARP packet
fr om t he VLAN.
D e n y: The Sw it ch generat es log m essages w hen it discar ds an ARP packet fr om t he
VLAN.
Pe r m it : The Sw it ch generat es log m essages w hen it for war ds an ARP packet fr om t he
VLAN.
All: The Sw it ch generat es log m essages ever y t im e it r eceives an ARP packet fr om t he
VLAN.
Apply
Click App ly t o save your changes t o t he Sw it ch’s r un- t im e m em or y. The Sw it ch loses
t hese changes if it is t ur ned off or loses pow er, so use t he Sa v e link on t he t op nav igat ion
panel t o save your changes t o t he non- volat ile m em or y w hen you ar e done configur ing.
Cancel
Click t his t o r eset t he values in t his scr een t o t heir last - saved values.
Table 110
Advanced Applicat ion > I P Sour ce Guar d > I Pv 4 Sour ce Guar d Set up > ARP I nspect ion >
Configur e > VLAN ( cont inued)
LABEL
DESCRIPTION