1-1
1
IP Source Guard Configuration
When configuring IP Source Guard, go to these sections for information you are interested in:
z
IP Source Guard Overview
z
Configuring a Static Binding Entry
z
Configuring Dynamic Binding Function
z
Displaying and Maintaining IP Source Guard
z
IP Source Guard Configuration Examples
z
Troubleshooting IP Source Guard
IP Source Guard Overview
By filtering packets on a per-port basis, IP source guard prevents illegal packets from traveling through
the ports, so as to block illegal usages of network resources and improve the network security. For
example, IP source guard can prevent an illegal host from pretending to be a legal user to access the
network. With IP source guard enabled on a port, after receiving a packet, the port looks up the key
attributes (including source IP address, source MAC address and VLAN tag) of the packet in the binding
entries of the IP source guard. If there is a match, the port forwards the packet. Otherwise, the port
discards the packet.
IP source guard filters packets based on the following types of binding entries:
z
IP-port binding entry
z
MAC-port binding entry
z
IP-MAC-port binding entry
z
IP-VLAN-port binding entry
z
MAC-VLAN-port binding entry
z
IP-MAC-VLAN-port binding entry
You can manually set static binding entries, or use DHCP snooping to provide dynamic binding entries,
where the dynamic IP-MAC bindings are inherited from the DHCP client IP-MAC bindings recorded by
DCHP snooping on an interface.
Binding is on a per-port basis. After a binding entry is configured on a port, it is effective only to the port.
Enabling IP source guard on a port is mutually exclusive with adding the port to an aggregation group.
Configuring a Static Binding Entry
Follow these steps to configure a static binding entry:
Содержание S5810 Series
Страница 307: ...ii Configured Multicast Group Policy Fails to Take Effect 1 32...
Страница 648: ...1 8 Return to the upper directory Sysname cd Display the current working directory Sysname pwd flash...
Страница 812: ...1 7 Role Slave Sysname stack_3 DeviceD Device type S5810 50S MAC address 000f e200 1003...