Configuring Ip Source Guard; Overview; Static Ipsg Bindings - HPE FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Configuring IP source guard

Overview

IP source guard (IPSG) prevents spoofing attacks by using an IPSG binding table to match
legitimate packets. It drops packets that do not match the table. IPSG is a per-interface packet filter.
Configuring the feature on one interface does not affect packet forwarding on another interface.
The IPSG binding table can include global and interface-specific bindings. IPSG first uses the
interface-specific bindings to match packets. If no match is found, IPSG uses the global bindings.
The IPSG bindings fall into the following types:
IP.
MAC.
IP-MAC.
IPSG bindings can be static or dynamic.
Static bindings—Configured manually. Global IPSG supports only static IP-MAC bindings. For
more information about global static IPSG bindings, see
Dynamic bindings—Generated based on information from other modules. For more
information about dynamic bindings, see
As shown in
Figure 129 IPSG application
Valid host
1.1.1.1
Invalid host

Static IPSG bindings

Static IPSG bindings are configured manually. They are suitable for scenarios where few hosts exist
on a LAN and their IP addresses are manually configured. For example, you can configure a static
IPSG binding on an interface that connects to a server. This binding allows the interface to receive
packets only from the server.
Static IPSG bindings on an interface implement the following functions:
Filter incoming IPv4 or IPv6 packets on the interface.
Cooperate with ARP attack detection in IPv4 and ND attack detection in IPv6 for user validity
checking.
For information about ARP attack detection, see
information about ND attack detection, see
Static IPSG bindings can be global or interface-specific.
Global static binding—Binds the IP address and MAC address in system view. The binding
takes effect on all interfaces to filter packets for user spoofing attack prevention.
Figure
129, IPSG forwards only the packets that match an IPSG binding.
IPSG bindings
1.1.1.1
...
Configure the IP source guard
feature on the interface
"Static IPSG
"Dynamic IPSG
bindings."
IP network
"Configuring ARP attack
"Configuring ND attack
497
bindings."
protection." For
defense."

Advertisement

Table of Contents
loading

Table of Contents