Lantronix SISPM1040-xxxx-L3 Web User Guide
33856 Rev. A https://www.lantronix.com/ 220
Security > IP Source Guard > Configuration
This page provides IP Source Guard related configuration.
IP Source Guard is a secure feature used to restrict IP traffic on DHCP snooping untrusted ports by filtering traffic
based on the DHCP Snooping Table or manually configured IP Source Bindings. It helps prevent IP spoofing
attacks when a host tries to spoof and use the IP address of another host.
Mode: Set to on to enable the Global IP Source Guard or set to off to disable the Global IP Source Guard.
All configured ACEs will be lost when the mode is enabled. The default is off.
Port Mode Configuration: At the dropdown enable IP Source Guard on the desired ports. Only when both Global
Mode and Port Mode on a given port are enabled, IP Source Guard is enabled on this given port.
Max Dynamic Clients: Specify the maximum number of dynamic clients that can be learned on given port. This
value can be 0, 1, 2, or Unlimited. If the port mode is enabled and the value of max dynamic clients is 0, it means
only allow the IP packets forwarding that are matched in static entries on the specific port.
Buttons
Apply: Click to save changes.
Reset: Click to undo any changes made locally and revert to previously saved values.
Translate dynamic to static: Click to translate all dynamic entries to static entries.
Message: The new setting of max dynamic clients on some port maybe lost some dynamic entries. Do you want
to proceed anyway?