IP Security
DHCP Snooping
Context
DHCP snooping allows clients to obtain IP addresses from authorized DHCP servers. The device with DHCP snooping enabled can generate binding entries based on the IP and MAC addresses of DHCP clients.
Procedure
- Choose DHCP Snooping tab, as shown in Figure 5-208. and click the
- Turn on Global status to enable DHCP snooping globally.
By default, DHCP snooping is not enabled globally.
- Click New and select a trusted interface in the displayed dialog box.
- Click Apply to configure the selected interface as a trusted interface.
- Click a record in VLAN List to edit its DHCP snooping status. Turn on DHCP Snooping Status and click
to complete the configuration.
You can also select multiple records and click Enable or Disable to set DHCP snooping status in a batch.
- Choose Interface List tab, as shown in Figure 5-209. and click the
- Select an interface on the Interface List tab page and edit its DHCP snooping status. Turn on DHCP Snooping Status and click
to complete the configuration.
IPSG
Procedure
- Choose IPSG tab, as shown in Figure 5-210. and click the
- Select a port to be configured. Perform the following operations as required in the port area:
- Click a port icon. To deselect the port, click the port icon again.
- Drag the cursor to select consecutive ports in a batch.
- Click multiple port icons to select these ports, and click a port icon again to deselect the port.
- Select a slot where an LPU is located. All ports on the LPU are selected.
- Turn on IPSG status.
- Select an IP packet check item from IPSG matching option.
- Click Apply to complete the configuration.
DAI
Procedure
- Choose DAI tab, as shown in Figure 5-211. and click the
- Select a port to be configured. Perform the following operations as required in the port area:
- Click a port icon. To deselect the port, click the port icon again.
- Drag the cursor to select consecutive ports in a batch.
- Click multiple port icons to select these ports, and click a port icon again to deselect the port.
- Select a slot where an LPU is located. All ports on the LPU are selected.
- Turn on DAI status.
- Select an ARP packet check item from DAI matching option.
- Click Apply to complete the configuration.
Static Binding Table
Context
IPSG based on a static binding table filters out IP packets received by untrusted interfaces, to prevent network access from malicious hosts using stolen IP addresses.
Procedure
- Create a static binding entry.
- Delete a static binding entry.
- Choose Static Binding Table tab, as shown in Figure 5-212. and click the
- Select a record that you want to delete and click Delete. The system asks you whether to delete the record.
- Click OK.
Dynamic Binding Table
Procedure
- Choose Dynamic Binding Table tab, as shown in Figure 5-214. and click the
- Click Refresh to update dynamic binding entries.
One-Click Binding
Context
Procedure
- Configure static user binding entries based on ARP entry
information.
- Delete the user static binding entries generated based
on ARP entries.
- Choose One-Click Binding page is displayed, as shown in Figure 5-215. . The
- To unbind one static user binding entry, click Unbind; to unbind multiple static user binding entries, select the entries you want to unbind and click One-Click unbind.