ZyXEL Communications GS1510-24 Manual De Usuario

Descargar
Página de 204
GS1510 Series User’s Guide
103
C
H A P T E R
 
 18 
IP Source Guard
18.1  Overview
Use the IP source guard screens to filter unauthorized DHCP and ARP packets in 
your network. IP source guard uses a binding table to distinguish between the 
authorized and unauthorized DHCP and ARP packets in your network.
18.2  What You Can Do
• Use  the  DHCP Snooping screens (
) to filter 
unauthorized DHCP packets on the network and to build the binding table 
dynamically.
• Use  the  ARP Inspection screens (
) to filter 
unauthorized ARP packets on the network.
• Use  the  Binding Table screens (
) to manually enter 
static bindings and to convert dynamic bindings to static.
18.3  What You Need To Know
A binding in the IP source guard binding table contains these key attributes:
• MAC address
• VLAN  ID
• IP address
• Port  number
When the Switch receives an ARP packet, it looks up the appropriate MAC address, 
VLAN ID, IP address, and port number in the binding table. If there is a binding, 
the Switch forwards the packet. If there is not a binding, the Switch discards the 
packet.
The Switch builds the binding table by snooping DHCP packets (dynamic bindings) 
and from information provided manually by administrators (static bindings).