EasyManua.ls Logo

HP 5120 EI Switch Series User Manual

HP 5120 EI Switch Series
304 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #266 background imageLoading...
Page #266 background image
256
IP source guard configuration examples
Static IPv4 source guard binding entry configuration example
Network requirements
As shown in Figure 77, Host A and Host B are connected to ports GigabitEthernet 1/0/2 and
GigabitEthernet 1/0/1 of Device B respectively, Host C is connected to port GigabitEthernet 1/0/2 of
Device A, and Device B is connected to port GigabitEthernet 1/0/1 of Device A.
Configure static IPv4 source guard binding entries on Device A and Device B to meet the following
requirements:
On port GigabitEthernet 1/0/2 of Device A, only IP packets from Host C can pass.
On port GigabitEthernet 1/0/1 of Device A, only IP packets from Host A can pass.
On port GigabitEthernet 1/0/2 of Device B, only IP packets from Host A can pass.
On port GigabitEthernet 1/0/1 of Device B, only IP packets from Host B can pass.
Figure 77 Network diagram for configuring static IPv4 source guard binding entries
IP: 192.168.0.3/24
MAC : 0001-0203-0405
IP: 192.168.0.1/24
MAC: 0001-0203-0406
Host A
IP: 192.168.0.2/24
MAC: 0001-0203-0407
Host B
Host C
GE1/0/2
GE1/0/1
GE1/0/2
GE1/0/1
Device A
Device B
Configuration procedure
1. Configure Device A
# Configure the IP addresses of the interfaces (omitted).
# Configure port GigabitEthernet 1/0/2 of Device A to allow only IP packets with the source MAC
address of 0001-0203-0405 and the source IP address of 192.168.0.3 to pass.
<DeviceA> system-view
[DeviceA] interface gigabitethernet 1/0/2
[DeviceA-GigabitEthernet1/0/2] user-bind ip-address 192.168.0.3 mac-address 0001-0203-
0405
[DeviceA-GigabitEthernet1/0/2] quit
# Configure port GigabitEthernet 1/0/1 of Device A to allow only IP packets with the source MAC
address of 0001-0203-0406 and the source IP address of 192.168.0.1 to pass.
[DeviceA] interface gigabitethernet 1/0/1
[DeviceA-GigabitEthernet1/0/1] user-bind ip-address 192.168.0.1 mac-address 0001-0203-
0406
2. Configure Device B
# Configure the IP addresses of the interfaces (omitted).

Table of Contents

Question and Answer IconNeed help?

Do you have a question about the HP 5120 EI Switch Series and is the answer not in the manual?

HP 5120 EI Switch Series Specifications

General IconGeneral
ModelHP 5120 EI Switch Series
LayerLayer 3
Forwarding Rate96 Mpps
MAC Address Table Size16K
Power SupplyInternal
ManagementCLI, Web GUI, SNMP
FeaturesIPv6 support
Routing ProtocolRIP, OSPF, BGP
Security FeaturesACLs
Layer 3 FeaturesOSPF, BGP, VRRP
RedundancyVRRP
Operating Temperature0°C to 45°C
SFP Slots4
VLAN Support4094
Jumbo Frames9216 bytes

Summary

AAA Configuration

AAA Configuration Considerations and Task List

Outlines the tasks and considerations required for configuring AAA on a NAS device.

Configuring AAA Schemes

Details the process of configuring AAA schemes, including local, RADIUS, and HWTACACS schemes.

Configuring RADIUS and HWTACACS Schemes

Describes configuring RADIUS and HWTACACS schemes, specifying servers, shared keys, and parameters.

Configuring AAA Authentication, Authorization, and Accounting Methods

Details the configuration of authentication, authorization, and accounting methods for users within an ISP domain.

802.1X Configuration

Configuring 802.1X

Provides steps for enabling 802.1X, setting access control, and configuring guest/Auth-Fail VLANs.

Enabling 802.1X and Access Control

Details enabling 802.1X globally and on ports, along with specifying access control methods.

MAC Authentication Configuration

MAC Authentication Configuration Task List

Lists tasks for configuring MAC authentication, including basic setup and examples.

Basic Configuration for MAC Authentication

Covers the basic steps for configuring MAC authentication globally and on ports.

Portal Configuration

Configuring Layer 2 Portal Authentication

Details the steps to configure Layer 2 portal authentication, including VLAN assignment and Auth-Fail VLAN.

Triple Authentication Configuration

Configuring Triple Authentication

Provides steps to configure triple authentication by enabling portal, MAC, and 802.1X authentication.

Port Security Configuration

Enabling Port Security and Setting Mode

Provides steps to enable port security and set its mode, like autoLearn or secure.

User Profile Configuration

Creating and Enabling User Profiles

Details creating and enabling user profiles to apply configurations and restrict user behaviors.

Password Control Configuration

Password Control Configuration Task List

Lists tasks for configuring password control, including global, group, and local user settings.

Configuring Password Control

Details enabling password control features like aging, history, and complexity checking.

Public Key Configuration

Configuring the Local Asymmetric Key Pair

Details creating, destroying, displaying, and exporting local RSA or DSA key pairs.

PKI Configuration

PKI Configuration Task List

Lists tasks for configuring PKI, including entity DN, PKI domain, and certificate requests.

Configuring an Entity DN and PKI Domain

Details configuring entity DN parameters and PKI domains for certificate requests.

Submitting and Retrieving Certificates

Explains submitting certificate requests in auto/manual modes and retrieving certificates.

SSH2.0 Configuration

Configuring the Device as an SSH Server

Provides steps to configure the device as an SSH server, including key generation and user setup.

SSH Server Configuration Task List

Lists tasks for configuring the SSH server, such as key pair generation and enabling the server.

Configuring the Device as an SSH Client

Details configuring the device as an SSH client, including source IP and connection setup.

SFTP Configuration

Configuring the Device as an SFTP Server

Provides steps to enable and configure the device as an SFTP server.

Configuring the Device an SFTP Client

Details configuring the device as an SFTP client, including source IP and connection setup.

SSL Configuration

Configuring an SSL Server Policy

Details setting SSL parameters for a server, including PKI domain and cipher suites.

TCP Attack Protection Configuration

IP Source Guard Configuration

ARP Attack Protection Configuration

ND Attack Defense Configuration

Related product manuals