Ip Source Guard; Ip Source Guard Configuration - Planet Networking & Communication GS-6320 Series User Manual

L3 gigabit/10 gigabit managed switch
Table of Contents

Advertisement

• Unknown IPv6
Next-Headers
• Port Mode
Configuration

4.6.8 IP Source Guard

4.6.8.1 IP Source Guard Configuration

IP Source Guard is a secure feature used to restrict IP traffic on DHCP snooping untrusted ports by filtering traffic based on
the DHCP Snooping Table or manually configured IP Source Bindings. It helps prevent IP spoofing attacks when a host tries to
spoof and use the IP address of another host. This page provides IP Source Guard related configuration. The IP Source Guard
Configuration screen in
Figure 4-6-8-1
User's Manual of GS-6320 and MGS-6320 Managed Switches
Disabled: Disable DHCP snooping mode operation.
Indicates how Unknown IPv6 Next-Header values should be treated. The switch
needs to parse all IPv6 packets to a DHCPv6 client to determine if it is in fact a
DHCPv6 message. If an unknown IPv6 extension header is encountered the
parsing cannot continue. See RFC 7610, section 5, item 3 for details.
Possible options are:
Drop: Drop packets with unknown IPv6 extension headers. This is the most
secure option but may result in traffic disruptions.
Allow: Allow packets with unknown IPv6 extension headers. This is a less secure
option but prevents traffic disruptions.
Indicates the DHCPv6 snooping port mode.
Possible port modes are:
Trusted: Configures the port as trusted source of the DHCPv6 messages.
Untrusted: Configures the port as untrusted source of the DHCPv6 messages.
appears.
399

Advertisement

Table of Contents
loading

This manual is also suitable for:

Mgs-6320 series

Table of Contents