EasyManua.ls Logo

RayTalk RA-696 - Advanced

Default Icon
152 pages
Print Icon
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
4.4.3
A
dv
a
nc
e
d
AdvancedFirewallSettingscanbeenabledtosupplementthefirewallrules,providingextrasecurityenhancementagainstDHCP
andARPtrafficstraversingtheavailableinterfacesofthesystem.
DHCPSnooping:Whenenabled,DHCPpacketswillbevalidatedaga instpossiblethreatslikeDHCPstarvationattack.In
addition,theTrustedDHCPList(IP/MAC)canbeusedtospecifylegitimateDHCPserverstopreventrougeDHCPserver.
ARPInspection:Whenenabled,ARPpacketswillbevalidatedagainstARPspoofing.
o ForceDHCPoptionwhenenabled,theAPonlylearnsMAC/IPpairinformationthroughDHCPpackets.Sincedevices
configuredwithstaticIPaddressdoes notsendDHCPtraffic,
anyclient
withstaticIPaddresswillbeblockedfrom
internetaccessunlessitsMAC/IPpairislistedandenabledontheStaticList.
o BroadcastcanbeenabledtoletotherAP(withL2firewallfeature)learnthetrustedMAC/IP
o pairstoissueARPrequests.
o StaticListcanbeusedtoaddMACorMAC/IPpairsofdevicesthataretrustedtoissueARPrequest.Othernetwork
nodescanstillse ndtheirARPrequests;however,iftheirIPappearsonthestaticlist(withdifferentMAC),theirARP
requestswillbedroppedtopreventeavesdropping.
Ifanysettingsaremade,pleaseclickApplytosavetheconfigurationbeforeleavingthispage.
29

Table of Contents

Related product manuals