Ip Source Guard; Introduction - Raisecom ISCOM2600G-HI (A) Series Configuration Manual

Table of Contents

Advertisement

Raisecom
ISCOM2600G-HI (A) Series Configuration Guide
Step 3 (Optional) configure interface authorization mode to auto. By default, authentication is
required and thus does not need to be configured.
Raisecom(config-gigaethernet1/1/1)#dot1x auth-control auto
Step 4 Enable reauthentication, and configure the timer to 600s.
Raisecom(config-gigaethernet1/1/1)#dot1x reauthentication enable
Raisecom(config-gigaethernet1/1/1)#dot1x timer reauth-period 600
Checking results
Use the show dot1x command to show 802.1x configurations on the interface.
Raisecom#show dot1x gigaethernet 1/1/1
802.1x Global Admin State: enable
802.1x Authentication Method: chap
802.1x Authentication Mode: radius
Port gigaethernet1/1/1
--------------------------------------------------------
802.1X Port Admin State: enable
PAE: Authenticator
PortMethod: Portbased
PortControl: Auto
ReAuthentication: enable
KeepAlive: enable
QuietPeriod: 60(s)
ServerTimeout: 100(s)
SuppTimeout: 30(s)
ReAuthPeriod: 600(s)
TxPeriod: 30(s)
KeepalivePeriod: 60(s)

10.8 IP Source Guard

10.8.1 Introduction

IP Source Guard uses a binding table to defend against IP Source spoofing and solve IP
address embezzlement without identity authentication. IP Source Guard can cooperate with
DHCP Snooping to generate dynamic binding. In addition, you can configure static binding
manually. DHCP Snooping filters untrusted DHCP packets by establishing and maintaining
the DHCP binding database.
Raisecom Proprietary and Confidential
Copyright © Raisecom Technology Co., Ltd.
10 Security
438

Advertisement

Table of Contents
loading

Table of Contents