GS2210 Series User’s Guide
222
C
H A P T E R
2 6
IP Source Guard
26.1 IP Source Guard Overview
Use I Pv4 and I Pv6 sour ce guar d t o filt er unaut hor ized DHCP and ARP packet s in your net wor k.
I P sour ce guar d uses a binding t able t o dist inguish bet ween aut hor ized and unaut hor ized DHCP and
ARP packet s in your net wor k. A binding cont ains t hese key at t r ibut es:
•
MAC address
•
VLAN I D
•
I P addr ess
•
Por t num ber
When t he Swit ch r eceives a DHCP or ARP packet , it looks up t he appr opr iat e MAC addr ess, VLAN I D,
I P addr ess, and por t num ber in t he binding t able. I f t her e is a binding, t he Swit ch for war ds t he
packet . I f t her e is not a binding, t he Sw it ch discar ds t he packet .
26.1.1 What You Can Do
•
Use t he I P Sou r ce Gu a r d scr een (
) t o display t he links t o t he
configurat ion scr eens wher e you can configur e I Pv4 or I Pv6 sour ce guar d set t ings.
•
Use t he I Pv 4 Sou r ce Gu a r d Se t u p scr een (
) t o look at t he cur r ent
bindings for DHCP snooping and ARP inspect ion.
•
Use t he I P Sou r ce Gu a r d St a t ic Bin din g scr een (
) t o m anage st at ic
bindings for DHCP snooping and ARP inspect ion.
•
Use t he D H CP Sn oopin g screen (
) t o look at var ious st at ist ics about
t he DHCP snooping dat abase.
•
Use t his D H CP Sn oopin g Con figu r e scr een (
) t o enable DHCP
snooping on t he Sw it ch ( not on specific VLAN) , specify t he VLAN w her e t he default DHCP ser ver
is locat ed, and configur e t he DHCP snooping dat abase.
•
Use t he D H CP Sn oopin g Por t Con figu r e scr een (
) t o specify
w het her port s ar e t r ust ed or unt r ust ed por t s for DHCP snooping.
•
Use t he D H CP Sn oopin g V LAN Con figu r e scr een (
) t o enable DHCP
snooping on each VLAN and t o specify w het her or not t he Sw it ch adds DHCP r elay agent opt ion
82 infor m at ion t o DHCP r equest s t hat t he Sw it ch r elays t o a DHCP ser ver for each VLAN.
•
Use t he D H CP Sn oopin g V LAN Por t Con f igu r e scr een (
) t o apply a
differ ent DHCP opt ion 82 pr ofile t o cer t ain por t s in a VLAN.
•
Use t he ARP I n spe ct ion St a t u s scr een (
) t o look at t he cur r ent list of
MAC addr ess filt er s t hat w er e cr eat ed because t he Sw it ch ident ified an unaut horized ARP packet .
•
Use t he ARP I n spe ct ion V LAN St a t u s scr een (
) t o look at var ious
st at ist ics about ARP packet s in each VLAN.
Содержание GS2210-24
Страница 18: ...18 PART I User s Guide ...
Страница 33: ...33 PART II Technical Reference ...
Страница 110: ...Chapter 9 VLAN GS2210 Series User s Guide 110 Figure 83 Advanced Application VLAN Port Based VLAN Setup All Connected ...
Страница 111: ...Chapter 9 VLAN GS2210 Series User s Guide 111 Figure 84 Advanced Application VLAN Port Based VLAN Setup Port Isolation ...
Страница 178: ...Chapter 21 Classifier GS2210 Series User s Guide 178 Figure 127 Classifier Example ...
Страница 405: ...Chapter 51 Configure Clone GS2210 Series User s Guide 405 Figure 286 Management Configure Clone ...
Страница 433: ...Appendix D Legal Information GS2210 Series User s Guide 433 Environmental Product Declaration ...