Chapter 24 IP Source Guard
XS3900-48F User’s Guide
204
The Switch discards ARP packets on untrusted ports in the following situations:
• The sender’s information in the ARP packet does not match any of the current bindings.
• The rate at which ARP packets arrive is too high.
24.1.3.3 Syslog
The Switch can send syslog messages to the specified syslog server (
when it forwards or discards ARP packets. The Switch can consolidate log messages and send log
messages in batches to make this mechanism more efficient.
24.1.3.4 Configuring ARP Inspection
Follow these steps to configure ARP inspection on the Switch.
1
Configure DHCP snooping. See
.
Note: It is recommended you enable DHCP snooping at least one day before you enable
ARP inspection so that the Switch has enough time to build the binding table.
2
Enable ARP inspection on each VLAN.
3
Configure trusted and untrusted ports, and specify the maximum number of ARP packets that each
port can receive per second.
24.2 IP Source Guard
Use this screen to look at the current bindings for DHCP snooping and ARP inspection. Bindings are
used by DHCP snooping and ARP inspection to distinguish between authorized and unauthorized
packets in the network. The Switch learns the bindings by snooping DHCP packets (dynamic
bindings) and from information provided manually by administrators (static bindings). To open this
screen, click Advanced Application > IP Source Guard.
Figure 108
IP Source Guard
The following table describes the labels in this screen.
Table 83
IP Source Guard
LABEL
DESCRIPTION
Index
This field displays a sequential number for each binding.
MAC Address
This field displays the source MAC address in the binding.
IP Address
This field displays the IP address assigned to the MAC address in the binding.
Lease
This field displays how many days, hours, minutes, and seconds the binding is valid;
for example, 2d3h4m5s means the binding is still valid for 2 days, 3 hours, 4 minutes
and 5 seconds. This field displays infinity if the binding is always valid (for example, a
static binding).
Содержание XS-3900-48F
Страница 15: ...15 PART I User s Guide ...
Страница 16: ...16 ...
Страница 48: ...Chapter 2 Tutorials XS3900 48F User s Guide 48 ...
Страница 62: ...Chapter 4 The Web Configurator XS3900 48F User s Guide 62 ...
Страница 63: ...63 PART II Technical Reference ...
Страница 64: ...64 ...
Страница 227: ...Chapter 26 VLAN Mapping XS3900 48F User s Guide 227 ...
Страница 320: ...Appendix A Common Services XS3900 48F User s Guide 320 ...
Страница 332: ...Index XS3900 48F User s Guide 332 ...