Netgear FVX538v1 FVX538 Reference Manual - Page 93

IP/MAC Binding, Apply, Delete, Select All., Available MAC Addresses to be Blocked, Example, Security

Page 93 highlights

ProSafe VPN Firewall 200 FVX538 Reference Manual 6. Click Apply to save your settings. To remove an entry from the table, select the MAC address entry and click Delete. To select all the list of MAC addresses, click Select All. A checkmark will appear in the box to the left of each MAC address in the Available MAC Addresses to be Blocked table. IP/MAC Binding IP/MAC Binding allows you to bind an IP address to a MAC address and vice-versa. Some machines are configured with static addresses. To prevent users from changing their static IP addresses, IP/MAC Binding must be enabled on the router. If the router sees packets with a matching IP address, but with the inconsistent MAC address (or vice-versa), it will drop these packets. If users have enabled the logging option for IP/MAC Binding, these packets will be logged before they are dropped. The router will then display the total number of dropped packets that violated either the IP-to-MAC Binding or the MAC-to-IP Binding. Example: If three computers on the LAN are set up as follows: • Host1: MAC address (00:01:02:03:04:05) and IP address (192.168.10.10) • Host2: MAC address (00:01:02:03:04:06) and IP address (192.168.10.11) • Host3: MAC address (00:01:02:03:04:07) and IP address (192.168.10.12) If all the above host entries are added to the IP/MAC Binding table, the following scenarios indicate the possible outcome. • Host1: Matching IP & MAC address in IP/MAC Table. • Host2: Matching IP but inconsistent MAC address in IP/MAC Table. • Host3: Matching MAC but inconsistent IP address in IP/MAC Table. The router will block the traffic coming from Host2 and Host3, but allow the traffic coming from Host1 to any external network. The total count of dropped packets will be displayed. To invoke the IP/MAC Binding Table screen: 1. Select Security from the main menu and IP/MAC Binding from the sub-menu. The IP/MAC Binding screen will display. 2. Select the Yes radio box and click Apply. Make sure that you have enabled Firewall Logs and email. Firewall Protection and Content Filtering v1.0, March 2009 4-33

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240

ProSafe VPN Firewall 200 FVX538 Reference Manual
Firewall Protection and Content Filtering
4-33
v1.0, March 2009
6.
Click
Apply
to save your settings.
To remove an entry from the table, select the MAC address entry and click
Delete
.
To select all the list of MAC addresses, click
Select All.
A checkmark will appear in the box to the
left of each MAC address in the
Available MAC Addresses to be Blocked
table
.
IP/MAC Binding
IP/MAC Binding allows you to bind an IP address to a MAC address and vice-versa. Some
machines are configured with static addresses. To prevent users from changing their static IP
addresses, IP/MAC Binding must be enabled on the router. If the router sees packets with a
matching IP address, but with the inconsistent MAC address (or vice-versa), it will drop these
packets. If users have enabled the logging option for IP/MAC Binding, these packets will be
logged before they are dropped. The router will then display the total number of dropped packets
that violated either the IP-to-MAC Binding or the MAC-to-IP Binding.
Example
: If three computers on the LAN are set up as follows:
Host1: MAC address (00:01:02:03:04:05) and IP address (192.168.10.10)
Host2: MAC address (00:01:02:03:04:06) and IP address (192.168.10.11)
Host3: MAC address (00:01:02:03:04:07) and IP address (192.168.10.12)
If all the above host entries are added to the IP/MAC Binding table, the following scenarios
indicate the possible outcome.
Host1: Matching IP & MAC address in IP/MAC Table.
Host2: Matching IP but inconsistent MAC address in IP/MAC Table.
Host3: Matching MAC but inconsistent IP address in IP/MAC Table.
The router will block the traffic coming from Host2 and Host3, but allow the traffic coming from
Host1 to any external network. The total count of dropped packets will be displayed.
To invoke the IP/MAC Binding Table screen:
1.
Select
Security
from the main menu and
IP/MAC Binding
from the sub-menu. The
IP/MAC
Binding
screen will display.
2.
Select the
Yes
radio box and click
Apply.
Make sure that you have enabled
Firewall Logs and
email
.