4.4.3
A
dv
a
nc
e
d
AdvancedFirewallSettingscanbeenabledtosupplementthefirewallrules,providingextrasecurityenhancementagainstDHCP
andARPtrafficstraversingtheavailableinterfacesofthesystem.
DHCPSnooping:Whenenabled,DHCPpacketswillbevalidatedaga instpossiblethreatslikeDHCPstarvationattack.In
addition,theTrustedDHCPList(IP/MAC)canbeusedtospecifylegitimateDHCPserverstopreventrougeDHCPserver.
ARPInspection:Whenenabled,ARPpacketswillbevalidatedagainstARPspoofing.
o ForceDHCPoptionwhenenabled,theAPonlylearnsMAC/IPpairinformationthroughDHCPpackets.Sincedevices
configuredwithstaticIPaddressdoes notsendDHCPtraffic,
anyclient
withstaticIPaddresswillbeblockedfrom
internetaccessunlessitsMAC/IPpairislistedandenabledontheStaticList.
o BroadcastcanbeenabledtoletotherAP(withL2firewallfeature)learnthetrustedMAC/IP
o pairstoissueARPrequests.
o StaticListcanbeusedtoaddMACorMAC/IPpairsofdevicesthataretrustedtoissueARPrequest.Othernetwork
nodescanstillse ndtheirARPrequests;however,iftheirIPappearsonthestaticlist(withdifferentMAC),theirARP
requestswillbedroppedtopreventeavesdropping.
Ifanysettingsaremade,pleaseclickApplytosavetheconfigurationbeforeleavingthispage.