Chapter 12
| Security Measures
IPv6 Source Guard
– 364 –
◆
Table entries include a MAC address, IPv6 global unicast address, entry type
(Static-IPv6-SG-Binding, Dynamic-ND-Binding, Dynamic-DHCPv6-Binding),
VLAN identifier, and port identifier.
◆
Static addresses entered in the source guard binding table (using the Static
Binding page) are automatically configured with an infinite lease time.
Dynamic entries learned via DHCPv6 snooping are configured by the DHCPv6
server itself.
◆
If IPv6 source guard is enabled, an inbound packet’s source IPv6 address will be
checked against the binding table. If no matching entry is found, the packet
will be dropped.
◆
Filtering rules are implemented as follows:
■
If ND snooping and DHCPv6 snooping are disabled, IPv6 source guard will
check the VLAN ID, source IPv6 address, and port number. If a matching
entry is found in the binding table and the entry type is static IPv6 source
guard binding, the packet will be forwarded.
■
If ND snooping or DHCP snooping is enabled, IPv6 source guard will check
the VLAN ID, source IP address, and port number. If a matching entry is
found in the binding table and the entry type is static IPv6 source guard
binding, dynamic ND snooping binding, or dynamic DHCPv6 snooping
binding, the packet will be forwarded.
■
If IP source guard is enabled on an interface for which IPv6 source bindings
(dynamically learned via ND snooping or DHCPv6 snooping, or manually
configured) are not yet configured, the switch will drop all IPv6 traffic on
that port, except for ND packets and DHCPv6 packets allowed by DHCPv6
snooping.
■
Only IPv6 global unicast addresses are accepted for static bindings.
Parameters
These parameters are displayed:
◆
Port
– Port identifier (Range: 1-28/52)
◆
Filter Type
– Configures the switch to filter inbound traffic based on the
following options. (Default: Disabled)
■
Disabled
– Disables IPv6 source guard filtering on the port.
■
SIP
– Enables traffic filtering based on IPv6 global unicast source IPv6
addresses stored in the binding table.
◆
Max Binding Entry
– The maximum number of entries that can be bound to an
interface. (Range: 1-5; Default: 5)
■
This parameter sets the maximum number of IPv6 global unicast source
IPv6 address entries that can be mapped to an interface in the binding
table, including both dynamic entries discovered by ND snooping, DHCPv6
snooping (refer to the DHCPv6 Snooping commands in the
CLI Reference
Содержание GTL-2881
Страница 30: ...Figures 30 Figure 450 Showing RIP Peer Information 669 Figure 451 Resetting RIP Statistics 670 ...
Страница 34: ...Section I Getting Started 34 ...
Страница 48: ...Section II Web Configuration 48 Unicast Routing on page 651 ...
Страница 151: ...Chapter 4 Interface Configuration VLAN Trunking 151 Figure 69 Configuring VLAN Trunking ...
Страница 152: ...Chapter 4 Interface Configuration VLAN Trunking 152 ...
Страница 229: ...Chapter 8 Congestion Control Automatic Traffic Control 229 Figure 135 Configuring ATC Interface Attributes ...
Страница 230: ...Chapter 8 Congestion Control Automatic Traffic Control 230 ...
Страница 596: ...Chapter 14 Multicast Filtering Multicast VLAN Registration for IPv6 596 ...
Страница 620: ...Chapter 15 IP Configuration Setting the Switch s IP Address IP Version 6 620 ...
Страница 670: ...Chapter 18 Unicast Routing Configuring the Routing Information Protocol 670 Figure 451 Resetting RIP Statistics ...
Страница 672: ...Section III Appendices 672 ...
Страница 678: ...Appendix A Software Specifications Management Information Bases 678 ...
Страница 688: ...Appendix C License Statement GPL Code Statement Notification of Compliance 688 ...
Страница 696: ...Glossary 696 ...
Страница 706: ...GTL 2881 GTL 2882 E112016 ST R01 ...