
OLT2406 User’s Guide
224
C
HAPTER
27
IP Source Guard
27.1 IP Source Guard Overview
Use IP source guard to filter unauthorized DHCP and ARP packets in your network.
IP source guard uses a binding table to distinguish between authorized and unauthorized DHCP and
ARP packets in your network. A binding contains these key attributes:
• MAC address
• VLAN ID
• IP address
• Port number
When the OLT receives a DHCP or ARP packet, it looks up the appropriate MAC address, VLAN ID, IP
address, and port number in the binding table. If there is a binding, the OLT forwards the packet. If there
is not a binding, the OLT discards the packet.
27.1.1 What You Can Do
• Use the
IP Source Guard Setup
screen (
) to look at the current bindings for
DHCP snooping and ARP inspection.
• Use the
IP Source Guard Static Binding
screen (
) to manage static bindings
for DHCP snooping and ARP inspection.
• Use the
DHCP Snooping
screen (
) to look at various statistics about the DHCP
snooping database.
• Use this
DHCP Snooping Configure
screen (
) to enable DHCP snooping on
the OLT (not on specific VLAN), specify the VLAN where the default DHCP server is located, and
configure the DHCP snooping database.
• Use the
DHCP Snooping Port Configure
screen (
) to specify whether ports
are trusted or untrusted ports for DHCP snooping.
• Use the
DHCP Snooping VLAN Configure
) to enable DHCP
snooping on each VLAN and to specify whether or not the OLT adds DHCP relay agent option 82
information to DHCP requests that the OLT relays to a DHCP server for each VLAN.
• Use the
ARP Inspection Status
) to look at the current list of MAC
address filters that were created because the OLT identified an unauthorized ARP packet.
• Use the
ARP Inspection VLAN Status
screen (
) to look at various statistics
about ARP packets in each VLAN.
• Use the
ARP Inspection Log Status
) to look at log messages that
were generated by ARP packets and that have not been sent to the syslog server yet.
• Use the
ARP Inspection Configure
) to enable ARP inspection on the
OLT. You can also configure the length of time the OLT stores records of discarded ARP packets and
global settings for the ARP inspection log.
Summary of Contents for OLT2406
Page 4: ...Document Conventions OLT2406 User s Guide 4 Desktop Laptop Switch IP Phone Smart T V...
Page 32: ...Table of Contents OLT2406 User s Guide 32 Index 758...
Page 33: ...33 PART I Introduction and Hardware Installation...
Page 63: ...63 PART II Web Configurator...
Page 179: ...Chapter 21 Classifier OLT2406 User s Guide 179 Figure 112 Classifier Example...
Page 182: ...Chapter 22 Policy Rule OLT2406 User s Guide 182 Figure 113 Advanced Application Policy Rule...
Page 186: ...Chapter 22 Policy Rule OLT2406 User s Guide 186 Figure 114 Policy Example...
Page 248: ...Chapter 28 Loop Guard OLT2406 User s Guide 248 Figure 151 Advanced Application Loop Guard...
Page 393: ...393 PART III CLI Commands...
Page 581: ...Chapter 78 VoIP OLT2406 User s Guide 581...
Page 725: ...725 PART IV Troubleshooting Specifications Appendices and Index...