444
•
Global static binding
—Binds the IP address and MAC address in system view. The binding
takes effect on all interfaces to filter packets for user spoofing attack prevention.
•
Interface-specific
static
binding
—Binds the IP address, MAC address, VLAN, or any
combination of the items in interface view. The binding takes effect only on the interface to
check the validity of users who are attempting to access the interface.
Dynamic IPSG bindings
IPSG automatically obtains user information from other modules to generate dynamic bindings. The
source modules include ARP snooping, 802.1X, DHCP snooping, DHCPv6 snooping, DHCP relay
agent, DHCPv6 relay agent, and DHCP server.
For example, DHCP-based IPSG bindings are suitable for scenarios where hosts on a LAN obtain IP
addresses through DHCP. IPSG is configured on the DHCP server, the DHCP snooping device, or
the DHCP relay agent. It generates dynamic bindings based on the client bindings on the DHCP
server, the DHCP snooping entries, or the DHCP relay entries. IPSG allows only packets from the
DHCP clients to pass through.
Dynamic IPv4SG
Dynamic bindings generated based on different source modules are for different usages:
Interface types
Source modules
Binding usage
Layer 2 Ethernet port
DHCP snooping
802.1X
ARP snooping
Packet filtering.
Layer 3 Ethernet
interface/VLAN interface
DHCP relay agent
Packet filtering.
DHCP server
For cooperation with modules (such as the
authorized ARP module) to provide security
services.
For more information about 802.1X, see "
." For information about ARP snooping,
DHCP snooping, DHCP relay agent, and DHCP server, see
Layer 3—IP Services Configuration
Guide
.
Dynamic IPv6SG
Dynamic IPv6SG bindings generated based on the following source modules are for packet filtering:
Interface types
Source modules
Layer 2 Ethernet port
DHCPv6 snooping
802.1X
Layer 3 Ethernet interface/VLAN interface
DHCPv6 relay agent
For more information about 802.1X, see "Configuring 802.1X." For more information about DHCPv6
snooping and DHCPv6 relay agent, see
Layer 3—IP Services Configuration Guide
.
IPSG configuration task list
To configure IPv4SG, perform the following tasks:
Tasks at a glance
(Required.)
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...