Chapter14
AccessSecurity
Conguration
Accesssecuritycongurationcanassurethesafetyofsubscriberaccounts,preventillegal
usersfromaccessingthedevice,andillegaluser-sidepacketsfromattackingthedevice.
TheZXA10C300supportsthefollowingaccesssecurityfeatures:
lPortidentication
lMACaddressanti-spoong
lARPanti-spoong
lIPsourceguard
lSplithorizon
lMFF
lARPproxy
TableofContents
PortIdenticationConguration................................................................................
14-1
MACAddressAnti-SpoongConguration...............................................................
14-8
ConguringtheARPAnti-Spoong.........................................................................14-10
ConguringtheSplitHorizon..................................................................................14-11
ConguringtheIPSourceGuard............................................................................14-12
ConguringMFF....................................................................................................14-13
ConguringARPProxy...........................................................................................14-14
14.1PortIdenticationConguration
Thesystemprovidestheportidenticationmechanismtoimprovenetworksecurityand
preventuseraccountsfrombeingstolen.Thesystemimplementsportidentication
throughthefollowingtechniques:
lDHCPv4Layer-2RelayAgent
lPPPoEIntermediateAgent
lDHCPv6Layer-2RelayAgent
lNDPLIO
14.1.1ConfiguringthePortIdentification
Port-identicationistodenetheformatandcontentoftheCircuitID(CID)andRemote
ID(RID).
14-1
SJ-20130520164529-007|2013-06-30(R1.0)ZTEProprietaryandCondential