Set Up Ip/Mac Bindings - NETGEAR SRX5308 Reference Manual

Prosafe gigabit quad wan ssl vpn firewall
Hide thumbs Also See for SRX5308:
Table of Contents

Advertisement

To remove one or more entries from the table:
1.
Select the check box to the left of the MAC address that you want to delete, or click the
Select All table button to select all entries.
2.
Click the Delete table button.

Set Up IP/MAC Bindings

IP/MAC binding allows you to bind an IP address to a MAC address and vice versa. Some
computers or devices are configured with static addresses. To prevent users from changing
their static IP addresses, the IP/MAC binding feature needs to be enabled on the VPN
firewall. If the VPN firewall detects packets with a matching IP address but with the
inconsistent MAC address (or vice versa), the packets are dropped. If you have enabled the
logging option for the IP/MAC binding feature, these packets are logged before they are
dropped. The VPN firewall displays the total number of dropped packets that violate either
the IP-to-MAC binding or the MAC-to-IP binding.
Note:
You can bind IP addresses to MAC addresses for DHCP
assignment on the LAN Groups screen (see
Database
As an example, assume that three computers on the LAN are set up as follows:
Host1. MAC address (00:01:02:03:04:05) and IP address (192.168.10.10)
Host2. MAC address (00:01:02:03:04:06) and IP address (192.168.10.11)
Host3. MAC address (00:01:02:03:04:07) and IP address (192.168.10.12)
If all of the preceding host entry examples are added to the IP/MAC Bindings table, the
following scenarios indicate the possible outcome.
Host1. Matching IP address and MAC address in the IP/MAC Bindings table.
Host2. Matching IP address but inconsistent MAC address in the IP/MAC Bindings table.
Host3. Matching MAC address but inconsistent IP address in the IP/MAC Bindings table.
In this example, the VPN firewall blocks the traffic coming from Host2 and Host3, but allows
the traffic coming from Host1 to any external network. The total count of dropped packets is
displayed.
To set up IP/MAC bindings:
1.
Select Security > Address Filter > IP/MAC Binding. The IP/MAC Binding screen
displays. (See the following figure, which shows one binding in the IP/MAC Binding table
as an example.)
ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308
on page 68).
Firewall Protection
Manage the Network
129

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents