Dynamic Ipsg Bindings; Ipsg Configuration Task List - HPE FlexNetwork 5510 HI Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 5510 HI Series:
Table of Contents

Advertisement

Global static binding—Binds the IP address and MAC address in system view. The binding
takes effect on all interfaces to filter packets for user spoofing attack prevention.
Interface-specific static binding—Binds the IP address, MAC address, VLAN, or any
combination of the items in interface view. The binding takes effect only on the interface to
check the validity of users who are attempting to access the interface.

Dynamic IPSG bindings

IPSG automatically obtains user information from other modules to generate dynamic bindings. The
source modules include DHCP relay agent, DHCP snooping, DHCPv6 snooping, and DHCP server.
DHCP-based IPSG bindings are suitable for scenarios where hosts on a LAN obtain IP addresses
through DHCP. IPSG is configured on the DHCP snooping device or the DHCP relay agent. It
generates dynamic IPSG bindings based on the DHCP snooping entries or DHCP relay entries.
IPSG allows only packets from the DHCP clients to pass through.
Dynamic IPv4SG
Dynamic bindings generated based on different source modules are for different usages:
Interface types
Layer 2 Ethernet port
Layer 3 Ethernet interface/Layer
3
aggregate
interface
For information about DHCP snooping, DHCP relay agent, and DHCP server see Layer 3—IP
Services Configuration Guide.
Dynamic IPv6SG
IPv6SG on an interface obtains information from DHCPv6 snooping entries to generate bindings for
packet filtering.
For more information about DHCPv6 snooping, see Layer 3—IP Services Configuration Guide.
NOTE:
The switch supports only dynamic IPv4SG in the current release.

IPSG configuration task list

To configure IPv4SG, perform the following tasks:
Tasks at a glance
(Required.)
(Optional.)
Configuring a static IPv4SG binding
To configure IPv6SG, perform the following tasks:
Tasks at a glance
(Required.)
Source modules
DHCP snooping
DHCP relay agent
interface/VLAN
DHCP server
Enabling IPv4SG on an interface
Enabling IPv6SG on an interface
Binding usage
Packet filtering.
Packet filtering.
For cooperation with modules (such as the
ARP detection module) to provide security
services.
401

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents