Ip Source Guard - ZyXEL Communications GS3700 Series User Manual

Gbe l2+ switch
Hide thumbs Also See for GS3700 Series:
Table of Contents

Advertisement

25.1 IP Source Guard Overview
I P source guard uses a binding t able t o dist inguish bet ween aut horized and unaut horized DHCP and
ARP packet s in your net work. A binding cont ains t hese key at t ribut es:
MAC address
VLAN I D
I P address
Port num ber
When t he Swit ch receives a DHCP or ARP packet , it looks up t he appropriat e MAC address, VLAN I D,
I P address, and port num ber in t he binding t able. I f t here is a binding, t he Swit ch forwards t he
packet . I f t here is not a binding, t he Swit ch discards t he packet .
The Swit ch builds t he binding t able by snooping DHCP packet s ( dynam ic bindings) and from
inform at ion provided m anually by adm inist rat ors ( st at ic bindings) .
I P source guard consist s of t he following feat ures:
St at ic bindings. Use t his t o creat e st at ic binding s in t he binding t able.
DHCP snooping. Use t his t o filt er unaut horized DHCP packet s on t he net work and t o build t he
binding t able dynam ically.
ARP inspect ion. Use t his t o filt er unaut horized AR P packet s on t he net work.
I f you want t o use dynam ic bindings t o filt er unaut horized ARP packet s ( t ypical im plem ent at ion) ,
you have t o enable DHCP snooping before you enable ARP inspect ion.
25.1.1 What You Can Do
Use t he I P Sou r ce Gu a r d screen (
DHCP snooping and ARP inspect ion.
Use t he I P Sour ce Gua r d St a t ic Binding screen (
bindings for DHCP snooping and ARP inspect ion.
Use t he D H CP Sn oopin g screen (
t he DHCP snooping dat abase.
Use t his D H CP Sn oopin g Con figu r e screen (
snooping on t he Swit ch ( not on specific VLAN) , specify t he VLAN where t he default DHCP server
is locat ed, and configure t he DHCP snooping dat abase.
Use t he D H CP Sn oopin g Por t Con figur e screen (
whet her port s are t rust ed or unt rust ed port s for DHCP snooping.
C
HAPTER
Sect ion 25.2 on page
Sect ion 25.5 on page
Sect ion 25.6 on page
GS3700/XGS3700 Series User's Guide
265

IP Source Guard

267) t o look at t he current bindings for
Sect ion 25.4 on page
269) t o m anage st at ic
271) t o look at various st at ist ics about
273) t o enable DHCP
Sect ion 25.6.1 on page
275) t o specify
2 5

Advertisement

Table of Contents
loading

This manual is also suitable for:

Xgs3700 series

Table of Contents