Filters - Advantech EKI-9516P-HV User Manual

Eki-9500 series
Table of Contents

Advertisement

The following table describes the items in the previous figure.
Item
VLAN ID
DHCP Drops
ACL Drops
DHCP Permits
ACL Permits
Bad Source MAC
Bad Dest MAC
Invalid IP
Forwarded
Dropped
Refresh
4.4.6

Filters

Static MAC filtering allows you to associate a MAC address with a VLAN and set of
source ports and destination ports. (The availability of source and destination port fil-
ters is subject to platform restrictions). Any packet with a static MAC address in a
specific VLAN is admitted only if the ingress port is included in the set of source
ports; otherwise the packet is dropped. If admitted, the packet is forwarded to all the
ports in the destination list.
4.4.6.1
MAC Filters
Use the Static MAC Filter Summary page to view, create, edit, and remove static
MAC filters on the device. A MAC filter is a security mechanism that allows Ethernet
frames that match the filter criteria (destination MAC address and VLAN ID) to be
received and transmitted only on certain ports.
Description
The DAI-enabled VLAN associated with the rest of the information in
the row. When DAI is enabled on a VLAN, DAI is enabled on all inter-
faces that are members of that VLAN.
The number of ARP packets that have been dropped by DAI because
no matching DHCP snooping binding entry was found in the DHCP
snooping database.
The number of ARP packets that have been dropped by DAI because
the sender IP address and sender MAC address in the ARP packet did
not match any rules in the ARP ACL associated with this VLAN. The
static flag on this VLAN is enabled, which means ARP packets that fail
to match an ARP ACL rule are dropped immediately and are not
checked against the DHCP snooping database for further validation.
The number of ARP packets that were forwarded by DAI because a
matching DHCP snooping binding entry was found in the DHCP
snooping database.
The number of ARP packets that were forwarded by DAI because the
sender IP address and sender MAC address in the ARP packet
matched a rule in the ARP ACL associated with this VLAN.
The number of ARP packets that were dropped by DAI because the
sender MAC address in ARP packet did not match the source MAC
address in the Ethernet header.
The number of ARP packets that were dropped by DAI because the
target MAC address in the ARP reply packet did not match the destina-
tion MAC address in the Ethernet header.
The number of ARP packets that were dropped by DAI because the
sender IP address in the ARP packet or target IP address in the ARP
reply packet was invalid. The following IP addresses are considered
invalid:
0.0.0.0
255.255.255.255
All IP multicast addresses
All class E addresses (240.0.0.0/4)
Loopback addresses (in the range 127.0.0.0/8)
The total number of valid ARP packets forwarded by DAI.
The total number of invalid ARP packets dropped by DAI.
Click Refresh to update the screen.
175
EKI-9500 Series User Manual

Advertisement

Table of Contents
loading

Table of Contents