21.1 IP/MAC Binding Overview
IP address to MAC address binding helps ensure that only the intended devices get to use privileged
IP addresses. The UAG uses DHCP to assign IP addresses and records to MAC address it assigned
each IP address. The UAG then checks incoming connection attempts against this list. A user
cannot manually assign another IP to his computer and use it to connect to the UAG.
Suppose you configure access privileges for IP address 172.16.1.27 and use static DHCP to assign
it to Bob's computer's MAC address of 12:34:56:78:90:AB. IP/MAC binding drops traffic from any
computer trying to use IP address 172.16.1.27 with another MAC address.
Figure 134 IP/MAC Binding Example
Bob
Jim
21.1.1 What You Can Do in this Chapter
• Use the Summary and Edit screens
addresses.
• Use the Exempt List screen
which the UAG does not apply IP/MAC binding.
21.1.2 What You Need to Know
DHCP
IP/MAC address bindings are based on the UAG's dynamic and static DHCP entries.
C
MAC: 12:34:56:78:90:AB
IP: 172.16.1.27
MAC: AB:CD:EF:12:34:56
IP: 172.16.1.27
(Section 21.2 on page
(Section 21.3 on page
UAG4100 User's Guide
208
HAPTER
IP/MAC Binding
209) to bind IP addresses to MAC
211) to configure ranges of IP addresses to
2 1