Chapter 4. Security; Ip Source Guard; 4-1.1 Configuration - ZyXEL Communications XGS3600 Series Manual

Gbe l2 switch with 10g gbe uplink
Table of Contents

Advertisement

Chapter 4.
This chapter describes all of the switch security configuration tasks to enhance the
security of local network including IP Source Guard, ARP Inspection, DHCP Snooping,
AAA, and etc..

4-1 IP Source Guard

IP Source Guard is a secure feature used to restrict IP traffic on DHCP snooping untrusted
ports by filtering traffic based on the DHCP Snooping Table or manually configured IP Source
Bindings. It helps prevent IP spoofing attacks when a host tries to spoof and use the IP
address of another host.
The section describes to configure the IP Source Guard detail parameters of the switch. You
could use the IP Source Guard configure to enable or disable with the Port of the switch.

4-1.1 Configuration

This section describes how to configure IP Source Guard setting including:
Mode (Enabled and Disabled)
Maximum Dynamic Clients (0, 1, 2, Unlimited)
Web Interface
To configure an IP Source Guard Configuration in the web interface:
1. Select "Enabled" in the Mode of IP Source Guard Configuration.
2. Select "Enabled" of the specific port in the Mode of Port Mode
Configuration.
3. Select Maximum Dynamic Clients (0, 1, 2, Unlimited) of the specific port
in the Mode of Port Mode Configuration.
4. Click Apply.
Figure 4-1.1: The IP Source Guard Configuration
Security
XGS3600 Series User's Guide
256

Advertisement

Table of Contents
loading

This manual is also suitable for:

Xgs3600-26fXgs3600-28Xgs3600-28f

Table of Contents