Configuring A Static Ipv4Sg Binding; Excluding Ipv4 Packets From Ipsg Filtering - HPE FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Configuring a static IPv4SG binding

You can configure global static and interface-specific static IPv4SG bindings.
Global static bindings take effect on all interfaces.
Interface-specific static bindings take priority over global static bindings. An interface first uses the
static bindings on the interface to match packets. If no match is found, the interface uses the global
bindings.
Configuring a global static IPv4SG binding
Step
1.
Enter system view.
2.
Configure a global static
IPv4SG binding.
Configuring a static IPv4SG binding on an interface
Step
1.
Enter system view.
2.
Enter interface view.
3.
Configure a static
IPv4SG binding.

Excluding IPv4 packets from IPSG filtering

Typically, IPv4SG processes all incoming IPv4 packets and discards the packets that do not match
IPSG bindings on an interface. This task excludes IPv4 packets with specific source items from IPSG
filtering. You can specify source VLANs for IPSG filtering exemption in the current software version.
All IPv4 packets from the specified VLANs are forwarded without being processed by IPSG.
To exclude IPv4 packets with the specified source items from IPSG filtering:
Command
system-view
ip source binding ip-address
ip-address mac-address
mac-address
Command
system-view
interface interface-type
interface-number
ip source binding { ip-address
ip-address | ip-address
ip-address mac-address
mac-address | mac-address
mac-address } [ vlan vlan-id ]
500
Remarks
N/A
No global static IPv4SG bindings
exist.
Remarks
N/A
The following interface types are
supported:
Layer 2 Ethernet interface.
Layer 2 aggregate interface.
Layer 3 Ethernet interface.
VLAN interface.
By default, no static IPv4SG bindings
exist on an interface.
The vlan vlan-id option is supported only
in Layer 2 Ethernet interface view.
To configure a static IPv4SG binding for
the ARP attack detection feature, make
sure the following conditions are met:
The ip-address ip-address option,
the mac-address mac-address
option, and the vlan vlan-id option
must be specified.
ARP attack detection must be
enabled for the specified VLAN.
You can configure the same static
IPv4SG binding on different interfaces.

Advertisement

Table of Contents
loading

Table of Contents