ZyWALL / USG (ZLD) CLI Reference Guide
157
C
H A P T E R
2 3
IP/MAC Binding
23.1 IP/MAC Binding Overview
IP address to MAC address binding helps ensure that only the intended devices get to use privileged
IP addresses. The ZyWALL / USG uses DHCP to assign IP addresses and records to MAC address it
assigned each IP address. The ZyWALL / USG then checks incoming connection attempts against
this list. A user cannot manually assign another IP to his computer and use it to connect to the
ZyWALL / USG.
Suppose you configure access privileges for IP address 192.168.1.27 and use static DHCP to assign
it to Tim’s computer’s MAC address of 12:34:56:78:90:AB. IP/MAC binding drops traffic from any
computer with another MAC address that tries to use IP address 192.168.1.27.
23.2 IP/MAC Binding Commands
The following table lists the
ip-mac-binding
commands. You must use the
configure terminal
command to enter the configuration mode before you can use these commands.
Table 81
ip-mac-binding Commands
COMMAND
DESCRIPTION
[no] ip ip-mac-binding
interface_name
activate
Turns on IP/MAC binding for the specified interface. The
no
command turns
IP/MAC binding off for the specified interface.
[no] ip ip-mac-binding
interface_name
log
Turns on the IP/MAC binding logs for the specified interface. The
no
command turns IP/MAC binding logs off for the specified interface.
ip ip-mac-binding exempt
name
start-ip
end-ip
Adds a named IP range as being exempt from IP/MAC binding.
no ip ip-mac-binding exempt
name
Deletes the named IP range from the list of addresses that are exempt from
IP/MAC binding.
show ip ip-mac-binding
interface_name
Shows whether IP/MAC binding is enabled or disabled for the specified
interface.
show ip ip-mac-binding all
Shows whether IP/MAC binding is enabled or disabled for all interfaces.
show ip ip-mac-binding status
interface_name
Displays the current IP/MAC bindings for the specified interface.
show ip ip-mac-binding status all
Displays the current IP/MAC bindings for all interfaces.
show ip ip-mac-binding exempt
Shows the current IP/MAC binding exempt list.
ip ip-mac-binding clear-drop-count
interface_name
Resets the packet drop counter for the specified interface.
debug ip ip-mac-binding activate
Turns on the IP/MAC binding debug logs.
no debug ip ip-mac-binding activate
Turns off the IP/MAC binding debug logs.
Summary of Contents for ZyWALL USG Series
Page 19: ...19 PART I Introduction ...
Page 20: ...20 ...
Page 38: ...Chapter 2 User and Privilege Modes ZyWALL USG ZLD CLI Reference Guide 38 ...
Page 39: ...39 PART II Reference ...
Page 40: ...40 ...
Page 48: ...Chapter 4 Status ZyWALL USG ZLD CLI Reference Guide 48 ...
Page 52: ...Chapter 5 Registration ZyWALL USG ZLD CLI Reference Guide 52 ...
Page 128: ...Chapter 15 Route ZyWALL USG ZLD CLI Reference Guide 128 ...
Page 136: ...Chapter 17 Zones ZyWALL USG ZLD CLI Reference Guide 136 ...
Page 140: ...Chapter 18 DDNS ZyWALL USG ZLD CLI Reference Guide 140 ...
Page 148: ...Chapter 20 HTTP Redirect ZyWALL USG ZLD CLI Reference Guide 148 ...
Page 152: ...Chapter 21 ALG ZyWALL USG ZLD CLI Reference Guide 152 ...
Page 156: ...Chapter 22 UPnP ZyWALL USG ZLD CLI Reference Guide 156 ...
Page 159: ...Chapter 23 IP MAC Binding ZyWALL USG ZLD CLI Reference Guide 159 ...
Page 178: ...Chapter 25 Secure Policy ZyWALL USG ZLD CLI Reference Guide 178 ...
Page 218: ...Chapter 32 Application Patrol ZyWALL USG ZLD CLI Reference Guide 218 ...
Page 236: ...Chapter 34 IDP Commands ZyWALL USG ZLD CLI Reference Guide 236 ...
Page 246: ...Chapter 35 Content Filtering ZyWALL USG ZLD CLI Reference Guide 246 ...
Page 256: ...Chapter 36 Anti Spam ZyWALL USG ZLD CLI Reference Guide 256 ...
Page 262: ...Chapter 37 SSL Inspection ZyWALL USG ZLD CLI Reference Guide 262 ...
Page 268: ...Chapter 38 Device HA ZyWALL USG ZLD CLI Reference Guide 268 ...
Page 284: ...Chapter 41 Addresses ZyWALL USG ZLD CLI Reference Guide 284 ...
Page 288: ...Chapter 42 Services ZyWALL USG ZLD CLI Reference Guide 288 ...
Page 302: ...Chapter 46 Authentication Server ZyWALL USG ZLD CLI Reference Guide 302 ...
Page 338: ...Chapter 52 System Remote Management ZyWALL USG ZLD CLI Reference Guide 338 ...
Page 358: ...Chapter 53 File Manager ZyWALL USG ZLD CLI Reference Guide 358 ...
Page 372: ...Chapter 56 Session Timeout ZyWALL USG ZLD CLI Reference Guide 372 ...
Page 374: ...Chapter 57 Diagnostics ZyWALL USG ZLD CLI Reference Guide 374 ...
Page 384: ...Chapter 59 Maintenance Tools ZyWALL USG ZLD CLI Reference Guide 384 ...
Page 426: ...List of Commands Alphabetical ZyWALL USG ZLD CLI Reference Guide 426 ...