
Security Measures
184
Instruction Manual - NXA-ENET8-POE+
Perform these steps to set the IP Source Guard filter for ports:
1.
Click
Security
> IP
Source Guard
>
General
.
2.
Set the required filtering type, set the table type to use ACL or MAC address binding, and then set the maximum binding
entries for each port.
3.
Click
Apply
.
Configuring Static Bindings for IPv4 Source Guard
Use the Security > IP Source Guard > Static Binding (Configure ACL Table and Configure MAC Table) pages to bind a static address
to a port. Table entries include a MAC address, IP address, lease time, entry type (Static, Dynamic), VLAN identifier, and port
identifier. All static entries are configured with an infinite lease time, which is indicated with a value of zero in the table.
Command Usage
Table entries include a MAC address, IP address, lease time, entry type (Static-IP- SG-Binding, Dynamic-DHCP-Binding),
VLAN identifier, and port identifier.
Static addresses entered in the source guard binding table are automatically configured with an infinite lease time.
When source guard is enabled, traffic is filtered based upon dynamic entries learned via DHCP snooping, or static addresses
configured in the source guard binding table.
An entry with same MAC address and a different VLAN ID cannot be added to the binding table.
Static bindings are processed as follows:
A valid static IP source guard entry will be added to the binding table in ACL mode if one of the following conditions is true:
If there is no entry with the same VLAN ID and MAC address, a new entry is added to the binding table using the type
static IP source guard binding
.
If there is an entry with the same VLAN ID and MAC address, and the type of entry is static IP source guard binding, then
the new entry will replace the old one.
If there is an entry with the same VLAN ID and MAC address, and the type of the entry is dynamic DHCP snooping
binding, then the new entry will replace the old one and the entry type will be changed to static IP source guard binding.
A valid static IP source guard entry will be added to the binding table in MAC mode if one of the following conditions are
true:
If there is no binding entry with the same IP address and MAC address, a new entry will be added to the binding table
using the type of static IP source guard binding entry.
If there is a binding entry with same IP address and MAC address, then the new entry shall replace the old one.
Only unicast addresses are accepted for static bindings.
The following table lists the options on this page:
FIG. 213
Setting the Filter Type for IPv4 Source Guard
Security - IP Source Guard (Static Binding) Options
Add - Configure ACL Table
Port
The port to which a static entry is bound.
VLAN
ID of a configured VLAN (Range: 1-4094)
MAC Address
A valid unicast MAC address
IP Address
A valid unicast IP address, including class types A, B or C.
Add - Configure MAC Table
MAC Address
A valid unicast MAC address
VLAN
ID of a configured VLAN or a range of VLANs. (Range: 1-4094)
IP Address
A valid unicast IP address, including class types A, B or C.
Port
The port to which a static entry is bound. Specify a physical port number or list of port numbers.
Separate nonconsecutive port numbers with a comma and no spaces; or use a hyphen to
designate a range of port numbers. (Range: 1-10/28)
Show
MAC Address
Physical address associated with the entry.
IP Address
IP address corresponding to the client.