What You Need To Know - ZyXEL Communications GS2210-8 User Manual

Gbe smart managed switch. gs2210 series
Table of Contents

Advertisement

Use t he ARP I n spe ct ion Log St a t u s screen (
t hat were generat ed by ARP packet s and t hat have not been sent t o t he syslog server yet .
Use t he ARP I nspe ct ion Con figur e screen (
inspect ion on t he Swit ch. You can also configure t he lengt h of t im e t he Swit ch st ores records of
discarded ARP packet s and global set t ings for t he ARP inspect ion log.
Use t he ARP I nspe ct ion Por t Configur e screen (
whet her port s are t rust ed or unt rust ed port s for ARP inspect ion.
Use t he ARP I n spe ct ion VLAN Con figu r e screen (
inspect ion on each VLAN and t o specify when t he Swit ch generat es log m essages for receiving
ARP packet s from each VLAN.
Use t he I Pv6 Sour ce Binding St a t us screen (
I Pv6 dynam ic and st at ic bindings and t o rem ove dynam ic bindings based on I Pv6 address and/ or
I Pv6 prefix.
Use t he I Pv6 St a t ic Bin ding Se t u p screen (
I Pv6 source guard binding t able and m anage I Pv6 st at ic bindings.
Use t he I Pv6 Sou r ce Gu a r d Policy Se t u p screen (
source guard forward valid I Pv6 addresses and/ or I Pv6 prefixes t hat are st ored in t he binding
t able and allow or block dat a t raffic from all link- local addresses
Use t he I Pv6 Sou r ce Gua r d Por t Se t up screen (
configured I Pv6 source guard policies t o t he port s you specify.
Use t he I Pv6 Snoopin g Policy Se t up screen (
an I Pv6 source guard binding t able using a DHCPv6 snooping policy. A DHCPv6 snooping policy
let s t he Swit ch sniff DHCPv6 packet s sent from a DHCPv6 server t o a DHCPv6 client when it is
assigning an I Pv6 address.
Use t he I Pv6 Sn ooping VLAN Se t up screen (
snooping policy on a specific VLAN int erface.
Use t he I Pv6 D H CP Tr ust Se t u p screen (
t rust ed and unt rust ed for DHCP snooping.

26.1.2 What You Need to Know

The Swit ch builds t he binding t able by snooping DHCP packet s ( dynam ic bindings) and from
inform at ion provided m anually by adm inist rat ors ( st at ic bindings) .
I P source guard consist s of t he following feat ures:
St at ic bindings. Use t his t o creat e st at ic binding s in t he binding t able.
DHCP snooping. Use t his t o filt er unaut horized DHCP packet s on t he net work and t o build t he
binding t able dynam ically.
ARP inspect ion. Use t his t o filt er unaut horized AR P packet s on t he net work.
I f you want t o use dynam ic bindings t o filt er unaut horized ARP packet s ( t ypical im plem ent at ion) ,
you have t o enable DHCP snooping before you enable ARP inspect ion.
26.2 IP Source Guard Screen
Use t his screen t o go t o t he configurat ion screens where you can configure I Pv4 or I Pv6 source
guard set t ings. Click Adva nce d Applica t ion > I P Sou r ce Gu a r d in t he navigat ion panel.
Chapter 26 IP Source Guard
Sect ion 26.9 on page
Sect ion 26.10 on page
Sect ion 26.10.1 on page
Sect ion 26.12 on page
Sect ion 26.13 on page
Sect ion 26.15 on page
Sect ion 26.16 on page
Sect ion 26.17 on page
Sect ion 26.18 on page
GS2210 Series User's Guide
223
238) t o look at log m essages
240) t o enable ARP
Sect ion 26.10.2 on page
244) t o look at t he current
245) t o m anually creat e an
Sect ion 26.14 on page
248) t o apply
249) t o dynam ically creat e
251) t o enable a DHCPv6
252) t o specify which port s are
241) t o specify
243) t o enable ARP
247) t o have I Pv6

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Gs2210-8hpGs2210-48hpGs2210-24Gs2210-24hpGs2210-48

Table of Contents