Chapter 21 IP Source Guard
ONU User’s Guide
161
Trusted vs. Untrusted Ports
Every port is either a trusted port or an untrusted port for ARP inspection. The ONU does not
discard ARP packets on trusted ports for any reason. The ONU discards ARP packets on
untrusted ports if the sender’s information in the ARP packet does not match any of the current
bindings.
Syslog
The ONU can send syslog messages to the specified syslog server (
when it forwards or discards ARP packets. The ONU can consolidate log messages and send
log messages in batches to make this mechanism more efficient.
Configuring ARP Inspection
Follow these steps to configure ARP inspection on the ONU.
1
Configure static bindings so the ONU can distinguish between authorized and
unauthorized ARP packets.
2
Enable ARP inspection on the ONU.
3
Enable ARP inspection on each VLAN.
4
Configure trusted and untrusted ports, and specify the maximum number of ARP packets
that each port can receive per second.
21.2 IP Source Guard
Use this screen to look at the current bindings for ARP inspection. Bindings are used by ARP
inspection to distinguish between authorized and unauthorized packets in the network. The
ONU learns the bindings from information provided manually by administrators (static
bindings). To open this screen, click
Advanced Application > IP Source Guard
.
Figure 80
IP Source Guard
The following table describes the labels in this screen.
Table 55
IP Source Guard
LABEL
DESCRIPTION
Index
This field displays a sequential number for each binding.
MAC Address
This field displays the source MAC address in the binding.
IP Address
This field displays the IP address assigned to the MAC address in the
binding.
Lease
This field displays how many days, hours, minutes, and seconds the
binding is valid; for example,
2d3h4m5s
means the binding is still valid for
2 days, 3 hours, 4 minutes, and 5 seconds. This field displays
infinity
if the
binding is always valid (for example, a static binding).
Type
This field displays how the ONU learned the binding.
static
: This binding was learned from information provided manually by an
administrator.
Summary of Contents for ONU-2024 Series
Page 2: ......
Page 7: ...Safety Warnings ONU User s Guide 7 This product is recyclable Dispose of it properly...
Page 8: ...Safety Warnings ONU User s Guide 8...
Page 20: ...Table of Contents ONU User s Guide 20...
Page 28: ...List of Tables ONU User s Guide 28...
Page 30: ...30...
Page 38: ...Chapter 2 Hardware Installation and Connection ONU User s Guide 38...
Page 44: ...Chapter 3 Hardware Connections ONU User s Guide 44...
Page 46: ...46...
Page 64: ...Chapter 6 System Status and Port Statistics ONU User s Guide 64...
Page 76: ...Chapter 7 Basic Setting ONU User s Guide 76...
Page 78: ...78...
Page 108: ...Chapter 11 Spanning Tree Protocol ONU User s Guide 108...
Page 158: ...Chapter 20 Authentication Accounting ONU User s Guide 158...
Page 174: ...Chapter 22 Loop Guard ONU User s Guide 174...
Page 175: ...175 PART IV IP Application Static Route 177 Differentiated Services 181 DHCP 185...
Page 176: ...176...
Page 180: ...Chapter 23 Static Route ONU User s Guide 180...
Page 192: ...192...
Page 216: ...Chapter 27 Access Control ONU User s Guide 216...
Page 222: ...Chapter 29 Syslog ONU User s Guide 222...
Page 236: ...236...
Page 254: ...Appendix C Legal Information ONU User s Guide 254...
Page 260: ...Appendix D Customer Support ONU User s Guide 260...
Page 268: ...Index ONU User s Guide 268...