Dynamic Ipsg Bindings; Ipsg Configuration Task List - HPE Moonshot 45Gc Security Configuration Manual

Switch module
Table of Contents

Advertisement

Filter incoming IPv4 or IPv6 packets on the interface.
Cooperate with ARP detection in IPv4 for user validity checking.
For information about ARP detection, see "Configuring ARP attack protection."
Static IPSG bindings can be global or interface-specific. IPSG first uses the interface-specific
bindings to match packets. If no match is found, IPSG uses the global bindings.
Global static binding—Binds the IP address and MAC address in system view. The binding
takes effect on all interfaces to filter packets for user spoofing attack prevention.
Interface-specific static binding—Binds the IP address, MAC address, VLAN, or any
combination of the items in interface view. The binding takes effect only on the interface to
check the validity of users who are attempting to access the interface.

Dynamic IPSG bindings

IPSG automatically obtains user information from other modules to generate dynamic bindings. The
source modules include DHCP relay, DHCP snooping, DHCPv6 snooping, and DHCP server.
DHCP-based IPSG bindings are suitable for scenarios where hosts on a LAN obtain IP addresses
through DHCP. IPSG is configured on the DHCP snooping device or the DHCP relay agent. It
generates dynamic IPSG bindings based on the DHCP snooping entries or DHCP relay entries.
IPSG allows only packets from the DHCP clients to pass through.
Dynamic IPv4SG
Dynamic bindings generated based on different source modules are for different usages:
Interface types
Layer 2 Ethernet port
Layer 3 Ethernet interface/Layer
3 Ethernet subinterface/Layer 3
aggregate interface/VLAN
interface
For information about DHCP snooping, DHCP relay, and DHCP server see Layer 3—IP Services
Configuration Guide.
Dynamic IPv6SG
IPv6SG on an interface obtains information from DHCPv6 snooping entries to generate bindings for
packet filtering.
For more information about DHCPv6 snooping, see Layer 3—IP Services Configuration Guide.

IPSG configuration task list

To configure IPv4SG, perform the following tasks:
Tasks at a glance
(Required.)
(Optional.)
Configuring a static IPv4SG binding
To configure IPv6SG, perform the following tasks:
Source modules
DHCP snooping
DHCP relay agent
DHCP server
Enabling IPv4SG on an interface
Binding usage
Packet filtering.
Packet filtering.
For cooperation with modules (such as the
ARP detection module) to provide security
services.
392

Advertisement

Table of Contents
loading

Table of Contents