
Chapter 84 ARP Inspection
XS3800-28 User’s Guide
628
84.7 IPv6 Source Guard
The purpose of IPv6 source guard is to distinguish between authorized and unauthorized users by using a
binding table that validates the source of IPv6 traffic. The binding table can be manually created or be
learned through Dynamic Host Configuration Protocol version 6 snooping (DHCPv6 snooping). IPv6
source guard can deny IPv6 traffic from an unknown source. The IPv6 source guard binding table
includes:
• IPv6 address
• IPv6 prefix
• VLAN ID
• Port number
• MAC address
Enable IPv6 source guard on a port for the Switch to check incoming IPv6 packets on that port. A
packet is allowed when it matches any entry in the IPSG binding table. If a user tries to send IPv6 packets
to the Switch that do not match an entry in the IPSG binding table, the Switch will drop these packets.
The Switch forwards matching traffic normally. The IPv6 source guard related screens are available in
standalone mode.
84.8 IPv6 Source Binding Status
Use this screen to look at the current IPv6 dynamic and static bindings and to remove dynamic bindings
based on IPv6 address and/or IPv6 prefix. Bindings are used to distinguish between authorized and
unauthorized packets in the network. The Switch learns the bindings by snooping DHCP packets
(dynamic bindings) and from information provided manually by administrators (static bindings). To open
this screen, click
SECURITY
>
IPv6 Source Guard
>
IP Static Binding
>
IP Source Binding Status
.
Enabled
Select
Yes
to enable ARP inspection on the VLAN. Select
No
to disable ARP inspection on the
VLAN.
Log
Specify when the Switch generates log messages for receiving ARP packets from the VLAN.
None
: The Switch does not generate any log messages when it receives an ARP packet from
the VLAN.
Deny
: The Switch generates log messages when it discards an ARP packet from the VLAN.
Permit
: The Switch generates log messages when it forwards an ARP packet from the VLAN.
All
: The Switch generates log messages every time it receives an ARP packet from the VLAN.
Apply
Click
Apply
to save your changes to the Switch’s run-time memory. The Switch loses these
changes if it is turned off or loses power, so use the
Save
link on the top navigation panel to
save your changes to the non-volatile memory when you are done configuring.
Cancel
Click this to reset the values in this screen to their last-saved values.
Table 337 SECURITY > IPv4 Source Guard > ARP Inspection > ARP Insp. VLAN Setup (continued)
LABEL
DESCRIPTION
Summary of Contents for XS3800-28
Page 29: ...29 PART I User s Guide...
Page 54: ...54 PART II Technical Reference...
Page 88: ...Chapter 4 Web Configurator XS3800 28 User s Guide 88 Figure 51 Online Web Help...
Page 148: ...Chapter 20 Cloud Management XS3800 28 User s Guide 148 Figure 94 SYSTEM Cloud Management...
Page 263: ...Chapter 36 OAM XS3800 28 User s Guide 263 Figure 182 PORT OAM OAM Status OAM Details...
Page 540: ...Chapter 72 VRRP XS3800 28 User s Guide 540 Figure 434 VRRP Example 2 VRRP Status on Switch B...
Page 581: ...Chapter 77 Policy Rule XS3800 28 User s Guide 581 Figure 456 Policy Example...