Chapter 13: Security Measures
IPv4 Source Guard
– 352 –
the SIP-MAC option). If a matching entry is found in the binding
table and the entry type is static IP source guard binding, or
dynamic DHCP snooping binding, the packet will be forwarded.
•
If IP source guard if enabled on an interface for which IP source
bindings have not yet been configured (neither by static
configuration in the IP source guard binding table nor dynamically
learned from DHCP snooping), the switch will drop all IP traffic on
that port, except for DHCP packets.
P
ARAMETERS
These parameters are displayed:
•
Filter Type
– Configures the switch to filter inbound traffic based
source IP address, or source IP address and corresponding MAC
address. (Default: None)
•
None
– Disables IP source guard filtering on the port.
•
SIP
– Enables traffic filtering based on IP addresses stored in the
binding table.
•
SIP-MAC
– Enables traffic filtering based on IP addresses and
corresponding MAC addresses stored in the binding table.
•
Max Binding Entry
– The maximum number of entries that can be
bound to an interface. (Range: 1-5; Default: 5)
This parameter sets the maximum number of address entries that can
be mapped to an interface in the binding table, including both dynamic
entries discovered by DHCP snooping (see
) and static entries set by IP source guard (see
Static Bindings for IPv4 Source Guard” on page 353
).
W
EB
I
NTERFACE
To set the IP Source Guard filter for ports:
1.
Click Security, IP Source Guard, Port Configuration.
2.
Set the required filtering type for each port.
3.
Click Apply
Figure 13-67: Setting the Filter Type for IPv4 Source Guard
Содержание SSE-G2252
Страница 42: ...44 General IP Routing on page 627...
Страница 174: ...Chapter 6 VLAN Configuration Configuring VLAN Mirroring 178 Figure 6 27 Showing the VLANs to Mirror...
Страница 511: ...Chapter 14 Basic Administration Protocols UDLD Configuration 518 Figure 14 100 Displaying UDLD Neighbor Information...
Страница 603: ...Chapter 16 IP Configuration Setting the Switch s IP Address IP Version 6 609...
Страница 883: ...Chapter 24 General Security Measures Port based Traffic Segmentation 894...
Страница 989: ...Chapter 30 Congestion Control Commands Automatic Traffic Control Commands 1000 Console...
Страница 1007: ...Chapter 33 Address Table Commands 1019...
Страница 1137: ...Chapter 38 Quality of Service Commands 1150...
Страница 1366: ...Chapter 46 IP Routing Commands Global Routing Configuration 1381 Connected 2 Total 2 FIB 0 Console...