Ip Source Guard; Chapter 26 Ip Source Guard; Overview; What You Can Do - ZyXEL Communications GS2200-24 User Manual

Intelligent layer 2gbe switch
Hide thumbs Also See for GS2200-24:
Table of Contents

Advertisement

C
H A P T E R

26.1 Overview

Use IP source guard to filter unauthorized DHCP and ARP packets in your network.
IP source guard uses a binding table to distinguish between authorized and
unauthorized DHCP and ARP packets in your network. A binding contains these
key attributes:
• MAC address
• VLAN ID
• IP address
• Port number
When the Switch receives a DHCP or ARP packet, it looks up the appropriate MAC
address, VLAN ID, IP address, and port number in the binding table. If there is a
binding, the Switch forwards the packet. If there is not a binding, the Switch
discards the packet.

26.2 What You Can Do

• Use the IP Source Guard screen
current bindings for DHCP snooping and ARP inspection.
• Use the IP Source Guard Static Binding screen
manage static bindings for DHCP snooping and ARP inspection.
• Use the DHCP Snooping screen
statistics about the DHCP snooping database.
• Use this DHCP Snooping Configure screen
enable DHCP snooping on the Switch (not on specific VLAN), specify the VLAN
where the default DHCP server is located, and configure the DHCP snooping
database.
• Use the DHCP Snooping Port Configure screen
to specify whether ports are trusted or untrusted ports for DHCP snooping.
GS2200-24 User's Guide

IP Source Guard

(Section 26.4 on page
(Section 26.5 on page
(Section 26.6 on page
(Section 26.7 on page
(Section 26.7.1 on page
26
216) to look at the
217) to
219) to look at various
222) to
224)
215

Advertisement

Table of Contents
loading

Table of Contents