Chapter 26 IP Source Guard
GS2210 Series User’s Guide
255
26.19.1.4 Configuring DHCP Snooping
Follow t hese st eps t o configur e DHCP snooping on t he Sw it ch.
1
Enable DHCP snooping on t he Swit ch.
2
Enable DHCP snooping on each VLAN, and configure DHCP relay opt ion 82.
3
Configur e t r ust ed and unt r ust ed por t s, and specify t he m axim um num ber of DHCP packet s t hat
each por t can r eceive per second.
4
Configur e st at ic bindings.
26.19.2 ARP Inspection Overview
Use ARP inspect ion t o filt er unaut horized ARP packet s on t he net w ork. This can prevent m any kinds
of m an- in- t he- m iddle at t acks, such as t he one in t he follow ing exam ple.
Figure 177
Exam ple: Man- in- t he- m iddle At t ack
I n t his exam ple, com put er B t r ies t o est ablish a connect ion w it h com put er A. Com put er X is in t he
sam e br oadcast dom ain as com put er A and int er cept s t he ARP r equest for com put er A. Then,
com put er X does t he following t hings:
•
I t pr et ends t o be com put er A and r esponds t o com put er B.
•
I t pr et ends t o be com put er B and sends a m essage t o com put er A.
As a r esult , all t he com m unicat ion bet w een com put er A and com put er B passes t hr ough com put er
X . Com put er X can r ead and alt er t he infor m at ion passed bet w een t hem .
26.19.2.1 ARP Inspection and MAC Address Filters
When t he Sw it ch ident ifies an unaut hor ized ARP packet , it aut om at ically cr eat es a MAC addr ess
filt er t o block t raffic fr om t he sour ce MAC address and sour ce VLAN I D of t he unaut hor ized ARP
packet . You can configur e how long t he MAC addr ess filt er r em ains in t he Swit ch.
These MAC addr ess filt er s ar e differ ent t han r egular MAC addr ess filt er s (
) .
•
They ar e st or ed only in volat ile m em or y.
•
They do not use t he sam e space in m em or y t hat r egular MAC addr ess filt er s use.
•
They appear only in t he ARP I n spe ct ion scr eens and com m ands, not in t he M AC Addr e ss
Filt e r scr eens and com m ands.
A
X
B
Содержание GS2210-24
Страница 18: ...18 PART I User s Guide ...
Страница 33: ...33 PART II Technical Reference ...
Страница 110: ...Chapter 9 VLAN GS2210 Series User s Guide 110 Figure 83 Advanced Application VLAN Port Based VLAN Setup All Connected ...
Страница 111: ...Chapter 9 VLAN GS2210 Series User s Guide 111 Figure 84 Advanced Application VLAN Port Based VLAN Setup Port Isolation ...
Страница 178: ...Chapter 21 Classifier GS2210 Series User s Guide 178 Figure 127 Classifier Example ...
Страница 405: ...Chapter 51 Configure Clone GS2210 Series User s Guide 405 Figure 286 Management Configure Clone ...
Страница 433: ...Appendix D Legal Information GS2210 Series User s Guide 433 Environmental Product Declaration ...