EasyManua.ls Logo

Orion A10E - Configuring Interface Trust Status of IP Source Guard; Configuring IP Source Guide Binding; Default Configurations of IP Source Guard; Preparing for Configurations

Orion A10E
376 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
Orion Networks
A10E/A28E/A28F Configuration Guide
6 Security
Orion Networks
186
6.8.2 Preparing for configurations
Scenario
There are often some IP source spoofing attacks in network. For example, the attacker
pretends legal users to send IP packets to the server, or the attacker forges the source IP
address of another user to communicate. This makes the legitimate users cannot get network
services normally.
With IP Source Guard binding, you can filter and control packets forwarded by the interface,
prevent the illegal packets passing through the interface, thus to restrict the illegal use of
network resources and improve the interface security.
Prerequisite
Enable DHCP Snooping before if there is a DHCP user.
6.8.3 Default configurations of IP Source Guard
The default configuration of IP Source Guard is as below.
Function
Default value
IP Source Guide static binding
Disable
IP Source Guide dynamic binding
Disable
Interface trust status
Untrusted
6.8.4 Configuring interface trust status of IP Source Guard
Configure interface trust status of IP Source Guard for the A10E/A28E as below.
Step
Configuration
Description
1
Alpha-A28E#config
Enter global configuration mode.
2
Alpha-
A28E(config)#interface
port
port-id
Enter physical layer interface configuration
mode.
3
Alpha-A28E(config-
port)#ip verify source
trust
Configure the interface to a trusted interface.
6.8.5 Configuring IP Source Guide binding
Configuring static IP Source Guide binding
Configure IP Source Guide static binding for the A10E/A28E as below.

Table of Contents