C
HAPTER
14
| Security Measures
IP Source Guard
– 347 –
ES-4500G Series
C
OMMAND
U
SAGE
◆
Setting source guard mode to SIP (Source IP) or SIP-MAC (Source IP
and MAC) enables this function on the selected port. Use the SIP option
to check the VLAN ID, source IP address, and port number against all
entries in the binding table. Use the SIP-MAC option to check these
same parameters, plus the source MAC address. If no matching entry is
found, the packet is dropped.
N
OTE
:
Multicast addresses cannot be used by IP Source Guard.
◆
When enabled, traffic is filtered based upon dynamic entries learned via
), or static
addresses configured in the source guard binding table.
◆
If IP source guard is enabled, an inbound packet’s IP address (SIP
option) or both its IP address and corresponding MAC address (SIP-
MAC option) will be checked against the binding table. If no matching
entry is found, the packet will be dropped.
◆
Filtering rules are implemented as follows:
■
If DHCP snooping is disabled (see
), IP source guard will
check the VLAN ID, source IP address, port number, and source
MAC address (for the SIP-MAC option). If a matching entry is found
in the binding table and the entry type is static IP source guard
binding, the packet will be forwarded.
■
If DHCP snooping is enabled, IP source guard will check the VLAN
ID, source IP address, port number, and source MAC address (for
the SIP-MAC option). If a matching entry is found in the binding
table and the entry type is static IP source guard binding, or
dynamic DHCP snooping binding, the packet will be forwarded.
■
If IP source guard if enabled on an interface for which IP source
bindings have not yet been configured (neither by static
configuration in the IP source guard binding table nor dynamically
learned from DHCP snooping), the switch will drop all IP traffic on
that port, except for DHCP packets.
P
ARAMETERS
These parameters are displayed in the web interface:
◆
Filter Type
– Configures the switch to filter inbound traffic based
source IP address, or source IP address and corresponding MAC
address. (Default: None)
■
None
– Disables IP source guard filtering on the port.
■
SIP
– Enables traffic filtering based on IP addresses stored in the
binding table.
Содержание iPECS ES-4526G
Страница 1: ...USER GUIDE User Manual ES 4550G ES 4526G Managed Layer 3 Stackable GE Switch ...
Страница 38: ...CONTENTS 38 ES 4500G Series ...
Страница 58: ...SECTION I Getting Started 58 ES 4500G Series ...
Страница 70: ...CHAPTER 1 Introduction System Defaults 70 ES 4500G Series ...
Страница 84: ...CHAPTER 2 Initial Switch Configuration Managing System Files 84 ES 4500G Series Success Console ...
Страница 86: ...SECTION I Web Configuration 86 ES 4500G Series Multicast Filtering on page 413 ...
Страница 196: ...CHAPTER 6 VLAN Configuration Configuring MAC based VLANs 196 ES 4500G Series ...
Страница 204: ...CHAPTER 7 Address Table Settings Clearing the Dynamic Address Table 204 ES 4500G Series ...
Страница 228: ...CHAPTER 8 Spanning Tree Algorithm Configuring Interface Settings for MSTP 228 ES 4500G Series ...
Страница 230: ...CHAPTER 9 Rate Limit Configuration 230 ES 4500G Series Figure 106 Configuring Rate Limits ...
Страница 260: ...CHAPTER 12 Quality of Service Attaching a Policy Map to a Port 260 ES 4500G Series ...
Страница 478: ...CHAPTER 17 IP Configuration Setting the Switch s IP Address IP Version 6 478 ES 4500G Series ...
Страница 528: ...CHAPTER 20 IP Services Forwarding UDP Service Requests 528 ES 4500G Series ...
Страница 584: ...CHAPTER 21 Unicast Routing Configuring the Open Shortest Path First Protocol Version 2 584 ES 4500G Series ...
Страница 614: ...CHAPTER 22 Multicast Routing Configuring PIMv6 for IPv6 614 ES 4500G Series ...
Страница 628: ...CHAPTER 23 Using the Command Line Interface CLI Command Groups 628 ES 4500G Series ...
Страница 702: ...CHAPTER 26 SNMP Commands 702 ES 4500G Series ...
Страница 710: ...CHAPTER 27 Remote Monitoring Commands 710 ES 4500G Series ...
Страница 868: ...CHAPTER 34 Port Mirroring Commands Local Port Mirroring Commands 868 ES 4500G Series ...
Страница 890: ...CHAPTER 37 Address Table Commands 890 ES 4500G Series ...
Страница 1066: ...CHAPTER 43 LLDP Commands 1066 ES 4500G Series ...
Страница 1076: ...CHAPTER 44 Domain Name Service Commands 1076 ES 4500G Series ...
Страница 1286: ...CHAPTER 49 Multicast Routing Commands PIM Multicast Routing 1286 ES 4500G Series ...
Страница 1288: ...SECTION I Appendices 1288 ES 4500G Series ...
Страница 1293: ...APPENDIX A Software Specifications Management Information Bases 1293 ES 4500G Series UDP MIB RFC 2013 ...
Страница 1294: ...APPENDIX A Software Specifications Management Information Bases 1294 ES 4500G Series ...
Страница 1327: ...ES 4526G ES 4550G E042011 ST R01 150200000149A ...
Страница 1328: ...APRIL 2011 ISSUE 1 0 ...