Ip Source Guard; Chapter 27 Ip Source Guard; Ip Source Guard Overview; What You Can Do - ZyXEL Communications OLT2406 User Manual

2u temperature-hardened, 6-slot mini chassis gpon olt
Table of Contents

Advertisement

27.1 IP Source Guard Overview

Use IP source guard to filter unauthorized DHCP and ARP packets in your network.
IP source guard uses a binding table to distinguish between authorized and unauthorized DHCP and
ARP packets in your network. A binding contains these key attributes:
• MAC address
• VLAN ID
• IP address
• Port number
When the OLT receives a DHCP or ARP packet, it looks up the appropriate MAC address, VLAN ID, IP
address, and port number in the binding table. If there is a binding, the OLT forwards the packet. If there
is not a binding, the OLT discards the packet.

27.1.1 What You Can Do

• Use the IP Source Guard Setup screen
DHCP snooping and ARP inspection.
• Use the IP Source Guard Static Binding screen
for DHCP snooping and ARP inspection.
• Use the DHCP Snooping screen
snooping database.
• Use this DHCP Snooping Configure screen
the OLT (not on specific VLAN), specify the VLAN where the default DHCP server is located, and
configure the DHCP snooping database.
• Use the DHCP Snooping Port Configure screen
are trusted or untrusted ports for DHCP snooping.
• Use the DHCP Snooping VLAN Configure screen
snooping on each VLAN and to specify whether or not the OLT adds DHCP relay agent option 82
information to DHCP requests that the OLT relays to a DHCP server for each VLAN.
• Use the ARP Inspection Status screen
address filters that were created because the OLT identified an unauthorized ARP packet.
• Use the ARP Inspection VLAN Status screen
about ARP packets in each VLAN.
• Use the ARP Inspection Log Status screen
were generated by ARP packets and that have not been sent to the syslog server yet.
• Use the ARP Inspection Configure screen
OLT. You can also configure the length of time the OLT stores records of discarded ARP packets and
global settings for the ARP inspection log.
C

IP Source Guard

(Section 27.2 on page
(Section 27.3 on page
(Section 27.4 on page
227) to look at various statistics about the DHCP
(Section 27.5 on page
(Section 27.5.1 on page
(Section 27.5.2 on page
(Section 27.6 on page
(Section 27.7 on page
(Section 27.8 on page
(Section 27.9 on page
OLT2406 User's Guide
224
H A P T E R
225) to look at the current bindings for
226) to manage static bindings
230) to enable DHCP snooping on
232) to specify whether ports
233) to enable DHCP
234) to look at the current list of MAC
235) to look at various statistics
236) to look at log messages that
238) to enable ARP inspection on the
27

Advertisement

Table of Contents
loading

Table of Contents