Configuring Ip Source Guard - LevelOne GSW-4876 User Manual

48 ge + 2 ge sfp web smart switch
Hide thumbs Also See for GSW-4876:
Table of Contents

Advertisement

| Configuring the Switch
C
4
HAPTER
Configuring Security
C
IP
ONFIGURING
S
G
OURCE
UARD
W
I
EB
NTERFACE
To configure DHCP Relay:
Click Advanced Configuration, Security, Network, DHCP, Relay.
1.
Enable the DHCP relay function, specify the DHCP server's IP address,
2.
enable Option 82 information mode, and set the policy by which to
handle relay information found in client packets.
Click Save.
3.
Figure 36: DHCP Relay Configuration
IP Source Guard is a security feature that filters IP traffic on network
interfaces based on manually configured entries in the IP Source Guard
table, or dynamic entries in the DHCP Snooping table when enabled (see
"Configuring DHCP
Snooping"). IP source guard can be used to prevent
traffic attacks caused when a host tries to use the IP address of a neighbor
to access the network.
C
G
ONFIGURING
LOBAL AND
Use the IP Source Guard Configuration page to filter traffic on an insecure
port which receives messages from outside the network or fire wall, and
therefore may be subject to traffic attacks caused by a host trying to use
the IP address of a neighbor. IP Source Guard filters traffic type based on
the source IP address and MAC address pairs found in the DHCP Snooping
table, or based upon static entries configured in the IP Source Guard Table.
P
ATH
Advanced Configuration, Security, Network, IP Source Guard, Configuration
C
U
OMMAND
SAGE
When IP Source Guard is enabled globally and on a port, the switch
checks the VLAN ID, source IP address, and port number against all
entries in the DHCP Snooping binding table and IP Source Guard Static
Table. If no matching entry is found, the packet is dropped.
Multicast addresses cannot be used by IP Source Guard.
N
:
OTE
– 112 –
P
S
IP S
ORT
ETTINGS FOR
G
OURCE
UARD

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents