D-Link DGS-3200-16 User Manual - Page 112

IP-MAC-Port Binding, IMP Global Settings

Page 112 highlights

xStack® DGS-3200 Series Layer 2 Gigabit Ethernet Managed Switch IP-MAC-Port Binding The IP network layer uses a four-byte address. The Ethernet link layer uses a six-byte MAC address. Binding these two address types together allows the transmission of data between the layers. The primary purpose of IP-MAC-port binding is to restrict the access to a switch to a number of authorized users. Authorized clients can access a switch's port by either checking the pair of IPMAC addresses with the pre-configured database or if DHCP snooping has been enabled in which case the the switch will automatically learn the IP/MAC pairs by snooping DHCP packets and saving them to the IMPB white list. If an unauthorized user tries to access an IP-MAC binding enabled port, the system will block the access by dropping its packet. For the xStack® DGS3200 Series of switches, active and inactive entries use the same database. The maximum number of entries is 511. The creation of authorized users can be manually configured by CLI or Web. The function is port-based, meaning a user can enable or disable the function on the individual port. The IP-MAC-Port Binding folder contains five windows: IMP Global Settings, IMP Port Settings, IMP Entry Settings, DHCP Snooping Entries, and MAC Block List. IMP Global Settings Users can enable or disable the Trap/Log State and DHCP Snoop state on the Switch. The Trap/Log field will enable and disable the sending of trap/log messages for IP-MAC-port binding. When enabled, the Switch will send a trap message to the SNMP agent and the Switch log when an ARP packet is received that doesn't match the IP-MAC-port binding configuration set on the Switch. To view the following window, click Security > IP-MAC-Port Binding > IMP Global Settings: Figure 5 - 4. IMP Global Settings window The following parameters can be set: Parameter Description Trap / Log This field will enable and disable the sending of trap/log messages for IP-MAC-port binding. When Enabled, the Switch will send a trap message to the SNMP agent and the Switch log when an ARP packet is received that doesn't match the IP-MAC-port binding configuration set on the Switch. The default is Disabled. DHCP Snoop State Use the pull-down menu to enable or disable DHCP snooping for IP-MAC-port binding. The default is Disabled. Click Apply to implement the settings made. IMP Port Settings Select a port or a range of ports with the From Port and To Port fields. Enable or disable the port with the State, Allow Zero IP and Forward DHCP Packet field, and configure the port's Max Entry. To view the following window, click Security > IP-MAC-Port Binding > IMP Port Settings: 99

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273

xStack
®
DGS-3200 Series Layer 2 Gigabit Ethernet Managed Switch
99
IP-MAC-Port Binding
The IP network layer uses a four-byte address. The Ethernet link layer uses a six-byte MAC address. Binding these two address
types together allows the transmission of data between the layers. The primary purpose of IP-MAC-port binding is to restrict the
access to a switch to a number of authorized users. Authorized clients can access a switch’s port by either checking the pair of IP-
MAC addresses with the pre-configured database or if DHCP snooping has been enabled in which case the the switch will
automatically learn the IP/MAC pairs by snooping DHCP packets and saving them to the IMPB white list. If an unauthorized user
tries to access an IP-MAC binding enabled port, the system will block the access by dropping its packet. For the xStack
®
DGS-
3200 Series of switches, active and inactive entries use the same database. The maximum number of entries is 511. The creation
of authorized users can be manually configured by CLI or Web. The function is port-based, meaning a user can enable or disable
the function on the individual port.
The
IP-MAC-Port Binding
folder contains five windows:
IMP Global Settings
,
IMP Port Settings
,
IMP Entry Settings
,
DHCP Snooping Entries
, and
MAC Block List
.
IMP Global Settings
Users can enable or disable the Trap/Log State and DHCP Snoop state on the Switch. The Trap/Log
field will enable and disable
the sending of trap/log messages for IP-MAC-port binding. When enabled, the Switch will send a trap message to the SNMP
agent and the Switch log when an ARP packet is received that doesn’t match the IP-MAC-port binding configuration set on the
Switch.
To view the following window, click
Security
>
IP-MAC-Port
Binding
>
IMP Global Settings
:
Figure 5 - 4. IMP Global Settings window
The following parameters can be set:
Parameter
Description
Trap / Log
This field will enable and disable the sending of trap/log messages for IP-MAC-port binding.
When
Enabled
, the Switch will send a trap message to the SNMP agent and the Switch log
when an ARP packet is received that doesn’t match the IP-MAC-port binding configuration
set on the Switch. The default is
Disabled
.
DHCP Snoop State
Use the pull-down menu to enable or disable DHCP snooping for IP-MAC-port binding. The
default is
Disabled
.
Click
Apply
to implement the settings made.
IMP Port Settings
Select a port or a range of ports with the From Port and To Port fields. Enable or disable the port with the State, Allow Zero IP
and Forward DHCP Packet field, and configure the port’s Max Entry.
To view the following window, click
Security
>
IP-MAC-Port
Binding
>
IMP Port Settings
: