Dynamic Ipsg Bindings - HPE FlexNetwork 7500 Series Security Configuration Manual

Table of Contents

Advertisement

For information about ARP attack detection, see "Configuring ARP attack protection." For
information about ND attack detection, see "Configuring ND attack defense."
Static IPSG bindings can be global or interface-specific.
Global static binding—Binds the IP address and MAC address in system view. The binding
takes effect on all interfaces to filter packets for user spoofing attack prevention.
Interface-specific static binding—Binds the IP address, MAC address, VLAN, or any
combination of the items in interface view. The binding takes effect only on the interface to
check the validity of users who are attempting to access the interface.

Dynamic IPSG bindings

IPSG automatically obtains user information from other modules to generate dynamic bindings. The
source modules include ARP snooping, 802.1X, DHCP relay agent, DHCPv6 relay agent, DHCP
snooping, DHCPv6 snooping, DHCP server, and ND snooping.
For example, DHCP-based IPSG bindings are suitable for scenarios where hosts on a LAN obtain IP
addresses through DHCP. IPSG is configured on the DHCP server, the DHCP snooping device, or
the DHCP relay agent. It generates dynamic bindings based on the client bindings on the DHCP
server, the DHCP snooping entries, or the DHCP relay entries. IPSG allows only packets from the
DHCP clients to pass through.
Dynamic IPv4SG
Dynamic bindings generated based on different source modules are for different usages:
Interface types
Layer 2 Ethernet port/Layer 2
aggregate interface
Layer 3 Ethernet
interface/VLAN interface
For more information about 802.1X, see "Configuring 802.1X." For information about ARP snooping,
DHCP snooping, DHCP relay, and DHCP server, see Layer 3—IP Services Configuration Guide.
Dynamic IPv6SG
Dynamic IPv6SG bindings generated based on the following source modules are for packet filtering:
Interface types
Layer 2 Ethernet port
Layer 3 Ethernet interface/VLAN interface
For more information about DHCPv6 snooping, ND snooping, and DHCPv6 relay agent, see Layer
3—IP Services Configuration Guide.
Source modules
DHCP snooping
802.1X
ARP snooping
DHCP relay agent
DHCP server
Source modules
DHCPv6 snooping
ND snooping
DHCPv6 relay agent
403
Binding usage
Packet filtering.
For cooperation with modules to provide
security services.
Packet filtering.
Packet filtering.
For cooperation with modules (such as the
authorized ARP module) to provide security
services.

Advertisement

Table of Contents
loading

Table of Contents