D-Link DGS-3200-10 Product Manual - Page 136

IP-MAC-Port Binding (IMPB), General Overview, Common IP Management Security Issues - cli manual

Page 136 highlights

xStack® DGS-3200 Series Layer 2 Gigabit Ethernet Managed Switch IP-MAC-Port Binding (IMPB) General Overview The DGS-3200 Series switches offer IP-MAC-Port Binding (IMPB), a D-Link security application used most often on edge switches directly connected to network hosts. IMPB is also an integral part of D-Link's End-to-End Security Solution (E2ES). The primary purpose of IP-MAC-Port Binding is to restrict client access to a switch by enabling administrators to configure pairs of client MAC and IP addresses that are allowed to access networks through a switch. Specifically, IMPB binds together the fourbyte IP address and the six-byte Ethernet link layer MAC address to allow the transmission of data between the layers. The IMPB function is port-based, meaning that a use r can enable or disable the function on any individual port. Once IMPB is enabled on a switch port, the switch will restrict or allow client access by chec king the pair of IP-MAC addresses with the preconfigured database, also known as the "I MPB white lis t". If an unauthorized user tries to access a n IMPB-enabled port, the system will block access by dropping its packet. The creation of authorized users can be manually configured by CLI or Web. Common IP Management Security Issues Currently, certain limitations and issues in IP management structures can lead to serious security problems. Auditing mechanisms, such as syslo g, app lication lo g, firewall lo g, et c, are m ainly based on c lient IP i nformation. However, s uch l og i nformation i s meaningless if the client IP address can be easily changed. IP conflict, the most common problem in today's networks, is another major security concern. Without IMPB, any user can change an IP address manually and cause conflict with other resources, such as other PCs, core switches, routers or servers. Not only does this duplicate IP create an auditing issue, it also poses potential risk to the entire network. Auditing Problem 192.168.1.1 00E0-0211-1111 192.168.1.2 00E0-0211-2222 192.168.1.3 00E0-0211-3333 IP Conflict IP Conflict Figure 5 - 4. Illustration of Common IP Security Problems ARP spoofing attacks in which malicious users intercept traffic or interrupt connections by manipulating ARP packets are another serious ch allenge in secu ring t oday's network. Further information on how A RP sp oofing attacks wor k can be fo und i n t he Appendix, "Mitigating ARP Spoofing Attack via Packet Content ACL," located in the back of this manual. Solutions to Improve IP Management Security DGS-3200 Series switches have introduced IMPB technology to protect networks from attacks. By using IP-MAC-Port Binding, all packets are dropped by a switch when the MAC address, IP address, and connected port are not in the IMPB white list. IMPB allows the user to choose either ARP or ACL mode. In addition, an IMPB white list can be dynamically created with the DHCP snooping option. DHCP snoo ping is a g lobal settin g and can be en abled on top of ACL or AR P mode. Each option has it s advantages and disadvantages. ARP Mode In ARP M ode, a swi tch pe rforms AR P Packet In spection i n w hich i t checks t he IP -MAC pai rs i n AR P packets and denies unauthorized ones. An advantage of ARP mode is that it does not consume any ACL ru les on the switch. Nonetheless, since the switch only checks ARP packets, it cannot block unauthorized clients who do not send out ARP packets. 123

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302

xStack
®
DGS-3200 Series Layer 2 Gigabit Ethernet Managed Switch
123
IP-MAC-Port Binding (IMPB)
General Overview
The DGS-3200 Series switches offer IP-MAC-Port Binding (IMPB), a D-Link security application used most often on edge
switches directly connected to network hosts. IMPB is also an integral part of D-Link’s End-to-End Security Solution (E2ES). The
primary purpose of IP-MAC-Port Binding is to restrict client access to a switch by enabling administrators to configure pairs of
client MAC and IP addresses that are allowed to access networks through a switch. Specifically, IMPB binds together the four-
byte IP address and the six-byte Ethernet link layer MAC address to allow the transmission of data between the layers.
The IMPB function is port-based, meaning that a user can enable or disable the function on any individual port. Once IMPB is
enabled on a switch port, the switch will restrict or allow client access by checking the pair of IP-MAC addresses with the pre-
configured database, also known as the “IMPB white list”. If an unauthorized user tries to access an IMPB-enabled port, the
system will block access by dropping its packet. The creation of authorized users can be manually configured by CLI or Web.
Common IP Management Security Issues
Currently, certain limitations and issues in IP management structures can lead to serious security problems. Auditing mechanisms,
such as syslo g, app lication lo g, firewall lo g, et c, are m ainly based on client IP i nformation. However, s uch log i nformation i s
meaningless if the client IP address can be easily changed. IP conflict, the most common problem in today’s networks, is another
major security concern. Without IMPB, any user can change an IP address manually and cause conflict with other resources, such
as other PCs, core switches, routers or servers. Not only does this duplicate IP create an auditing issue, it also poses potential risk
to the entire network.
Figure 5 - 4. Illustration of Common IP Security Problems
ARP spoofing attacks in which malicious users intercept traffic or interrupt connections by manipulating ARP packets are another
serious ch allenge in secu ring t oday’s network. Further information on how A RP sp oofing attacks wor k can be fo und i n t he
Appendix, "Mitigating ARP Spoofing Attack via Packet Content ACL," located in the back of this manual.
Solutions to Improve IP Management Security
DGS-3200 Series switches have introduced IMPB technology to protect networks from attacks. By using IP-MAC-Port Binding,
all packets are dropped by a switch when the MAC address, IP address, and connected port are not in the IMPB white list. IMPB
allows the user to choose either ARP or ACL mode. In addition, an IMPB white list can be dynamically created with the DHCP
snooping option. DHCP snoo ping is a g
lobal setting and can be enabled on top of ACL or ARP mode. Each option has its
advantages and disadvantages.
ARP Mode
In ARP M ode, a swi tch pe rforms AR P Packet In spection i n w hich i t checks t he IP -MAC pai rs i n AR P packets and denies
unauthorized ones. An advantage of ARP mode is that it does not consume any ACL rules on the switch. Nonetheless, since the
switch only checks ARP packets, it cannot block unauthorized clients who do not send out ARP packets.
192.168.1.1
00E0-0211-1111
192.168.1.2
00E0-0211-2222
192.168.1.3
00E0-0211-3333
IP Conflict
Auditing
Problem
IP Conflict