Chapter 26 IP Source Guard
XGS4700-48F User’s Guide
265
• They appear only in the ARP Inspection screens and commands, not in the
MAC Address Filter screens and commands.
26.1.2.2 Trusted vs. Untrusted Ports
Every port is either a trusted port or an untrusted port for ARP inspection. This
setting is independent of the trusted/untrusted setting for DHCP snooping. You
can also specify the maximum rate at which the Switch receives ARP packets on
untrusted ports.
The Switch does not discard ARP packets on trusted ports for any reason.
The Switch discards ARP packets on untrusted ports in the following situations:
• The sender’s information in the ARP packet does not match any of the current
bindings.
• The rate at which ARP packets arrive is too high.
26.1.2.3 Syslog
The Switch can send syslog messages to the specified syslog server (
) when it forwards or discards ARP packets. The Switch can
consolidate log messages and send log messages in batches to make this
mechanism more efficient.
26.1.2.4 Configuring ARP Inspection
Follow these steps to configure ARP inspection on the Switch.
1
Configure DHCP snooping. See
Note: It is recommended you enable DHCP snooping at least one day before you
enable ARP inspection so that the Switch has enough time to build the binding
table.
2
Enable ARP inspection on each VLAN.
3
Configure trusted and untrusted ports, and specify the maximum number of ARP
packets that each port can receive per second.
26.2 IP Source Guard
Use this screen to look at the current bindings for DHCP snooping and ARP
inspection. Bindings are used by DHCP snooping and ARP inspection to distinguish
between authorized and unauthorized packets in the network. The Switch learns
Содержание XGS4700 Series
Страница 2: ......
Страница 8: ...Safety Warnings XGS4700 48F User s Guide 8...
Страница 24: ...Table of Contents XGS4700 48F User s Guide 24...
Страница 25: ...25 PART I User s Guide...
Страница 26: ...26...
Страница 32: ...Chapter 1 Getting to Know Your Switch XGS4700 48F User s Guide 32...
Страница 54: ...Chapter 3 Hardware Overview XGS4700 48F User s Guide 54...
Страница 97: ...97 PART II Technical Reference...
Страница 98: ...98...
Страница 104: ...Chapter 7 System Status and Port Statistics XGS4700 48F User s Guide 104...
Страница 118: ...Chapter 8 Basic Setting XGS4700 48F User s Guide 118...
Страница 138: ...Chapter 9 VLAN XGS4700 48F User s Guide 138...
Страница 142: ...Chapter 10 Static MAC Forward Setup XGS4700 48F User s Guide 142...
Страница 174: ...Chapter 14 Bandwidth Control XGS4700 48F User s Guide 174...
Страница 188: ...Chapter 17 Link Aggregation XGS4700 48F User s Guide 188...
Страница 198: ...Chapter 18 Port Authentication XGS4700 48F User s Guide 198...
Страница 216: ...Chapter 21 Policy Rule XGS4700 48F User s Guide 216...
Страница 260: ...Chapter 25 AAA XGS4700 48F User s Guide 260...
Страница 284: ...Chapter 26 IP Source Guard XGS4700 48F User s Guide 284...
Страница 316: ...Chapter 32 Error Disable XGS4700 48F User s Guide 316...
Страница 320: ...Chapter 33 Static Route XGS4700 48F User s Guide 320...
Страница 328: ...Chapter 35 RIP XGS4700 48F User s Guide 328...
Страница 384: ...Chapter 42 ARP Learning XGS4700 48F User s Guide 384...
Страница 420: ...Chapter 45 Access Control XGS4700 48F User s Guide 420...
Страница 426: ...Chapter 47 Syslog XGS4700 48F User s Guide 426...
Страница 434: ...Chapter 48 Cluster Management XGS4700 48F User s Guide 434...
Страница 438: ...Chapter 49 MAC Table XGS4700 48F User s Guide 438...
Страница 442: ...Chapter 50 IP Table XGS4700 48F User s Guide 442...
Страница 446: ...Chapter 52 Routing Table XGS4700 48F User s Guide 446...
Страница 454: ...Chapter 54 Troubleshooting XGS4700 48F User s Guide 454...
Страница 464: ...Chapter 55 Product Specifications XGS4700 48F User s Guide 464...
Страница 473: ...Appendix B Legal Information XGS4700 48F User s Guide 473...
Страница 474: ...Appendix B Legal Information XGS4700 48F User s Guide 474...