![Atop EH9711 Series Скачать руководство пользователя страница 77](http://html1.mh-extra.com/html/atop/eh9711-series/eh9711-series_user-manual_3004814077.webp)
Industrial Managed
Ethernet Switch – EH9711
User Manual
Page
77
of
223
Label
Description
Factory
Default
1
: TCP frames where the URG field is set must be able to match this entry.
Any
: Any value is allowed ("don't-care")
Table 2.47 Description of ACL Configuration with Ethernet Type Parameters
Label
Description
Factory
Default
EtherType
Filter
Specify the Ethernet type filter for this ACE.
Any
: No EtherType filter is specified (EtherType filter status is "don't-care").
Specific
: If you want to filter a specific EtherType filter with this ACE, you can enter a
specific EtherType value. A field for entering an EtherType value appears.
-
Ethernet
Type Value
When "Specific" is selected for the EtherType filter, you can enter a specific EtherType value.
The allowed range is
0x600
to
0xFFFF
but excluding 0x800(IPv4), 0x806(ARP) and
0x86DD(IPv6). A frame that hits this ACE matches this EtherType value.
-
2.5.2.7
IP Source Guard
IP Source Guard is a secure feature used to restrict IP traffic on DHCP snooping untrusted ports by filtering traffic based on
the DHCP Snooping Table or manually configured IP Source Bindings. It helps prevent IP spoofing attacks when a host tries
to spoof and use the IP address of another host. This is to prevent a malicious host from impersonating a legitimate host by
assuming the legitimate host’s IP address.
2.5.2.7.1
IP Source Guard Configuration
IP Source Guard Configuration
webpage is shown in Figure 2.60. For each port, select the option for
Mode
and
Max
Dynamic Clients
under the
Port Mode Configuration
table. Table 2.48 describe the options under
IP Source Guard
Configuration
.
Figure 2.60 Webpage to IP Source Guard Configuration