
barox Kommunikation
40
5.2.3. IP Source Guard
Deployment and Configuration
An extended function for the protection of the terminal side is provided by using the IP Source
Guard function. This function links the predefined static IP address of the connected devices with
the examination of the MAC addresses of the source terminal devices. As shown in the following
screenshot this function is generally activated and can be adjusted on a per-port basis.
Once this function is switched on the configuration can be effected using static entries as shown
below.
The use of IP Source Guard enables the extended protection function by securing the ports by
means of the MAC and IP address. Compared to port security, where static MAC address entries
per port prevent a potential attack, IP Source Guard provides the verification of the IP address of
the connected devi
ce using static entries. The switch will block the port‘s network communication
where the connected device does not comply with the allocated MAC and IP address. This
means, that the attacker must know the MAC address and IP address of the device for gaini ng
access to the network.
Содержание L Series
Страница 50: ...barox Kommunikation 50...