Microsens MS453490M Management Guide User Manual

Page 338

Advertising
background image

C

HAPTER

14

| Security Measures

IP Source Guard

– 338 –

C

OMMAND

U

SAGE

Setting source guard mode to SIP (Source IP) or SIP-MAC (Source IP

and MAC) enables this function on the selected port. Use the SIP option

to check the VLAN ID, source IP address, and port number against all

entries in the binding table. Use the SIP-MAC option to check these

same parameters, plus the source MAC address. If no matching entry is

found, the packet is dropped.

N

OTE

:

Multicast addresses cannot be used by IP Source Guard.

When enabled, traffic is filtered based upon dynamic entries learned via

DHCP snooping (see

"DHCP Snooping" on page 342

), or static

addresses configured in the source guard binding table.

If IP source guard is enabled, an inbound packet’s IP address (SIP

option) or both its IP address and corresponding MAC address (SIP-

MAC option) will be checked against the binding table. If no matching

entry is found, the packet will be dropped.

Filtering rules are implemented as follows:

If DHCP snooping is disabled (see

page 345

), IP source guard will

check the VLAN ID, source IP address, port number, and source

MAC address (for the SIP-MAC option). If a matching entry is found

in the binding table and the entry type is static IP source guard

binding, the packet will be forwarded.

If DHCP snooping is enabled, IP source guard will check the VLAN

ID, source IP address, port number, and source MAC address (for

the SIP-MAC option). If a matching entry is found in the binding

table and the entry type is static IP source guard binding, or

dynamic DHCP snooping binding, the packet will be forwarded.

If IP source guard if enabled on an interface for which IP source

bindings have not yet been configured (neither by static

configuration in the IP source guard binding table nor dynamically

learned from DHCP snooping), the switch will drop all IP traffic on

that port, except for DHCP packets.

P

ARAMETERS

These parameters are displayed:

Filter Type – Configures the switch to filter inbound traffic based

source IP address, or source IP address and corresponding MAC

address. (Default: None)

None – Disables IP source guard filtering on the port.

SIP – Enables traffic filtering based on IP addresses stored in the

binding table.

Advertising