HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 171

Dynamic IPv4 source binding entries, IP source guard configuration task list

Page 171 highlights

For information about ARP detection, see "Configuring ARP attack protection." Dynamic IPv4 source binding entries IP source guard can automatically obtain user information from other modules to generate IPv4 binding entries. On interfaces configured with the dynamic IPv4 source guard function, IP source guard cooperates with different modules to generate IPv4 binding entries dynamically: • On an Ethernet port, IP source guard can cooperate with DHCP snooping, obtain the DHCP snooping entries generated when hosts dynamically obtain IP addresses, and generate IPv4 binding entries accordingly to filter packets. • On a VLAN interface, IP source guard can cooperate with the DHCP relay agent, obtain the DHCP relay entries generated when hosts obtain IP addresses across subnets, and generate IPv4 binding entries accordingly to filter packets. • On a VLAN interface, IP source guard can also cooperate with the DHCP server. It generates dynamic binding entries according to the user information recorded by the DHCP server during IP address allocation. Such binding entries do not filter packets directly but help other modules (such as the ARP detection module) to provide security services. For information about DHCP snooping, DHCP relay, and DHCP server see Layer 3-IP Services Configuration Guide. IP source guard configuration task list To configure IPv4 source guard, perform the following tasks: Tasks at a glance (Required.) Enabling IPv4 source guard on an interface (Optional.) Configuring a static IPv4 source guard binding entry on an interface To configure IPv6 source guard, perform the following tasks: Tasks at a glance (Required.) Enabling IPv6 source guard on an interface (Optional.) Configuring a static IPv6 source guard binding entry on an interface Configuring the IPv4 source guard function You cannot configure the IPv4 source guard function on a service loopback interface. If IPv4 source guard is enabled on an interface, you cannot assign the interface to a service loopback group. Enabling IPv4 source guard on an interface You must first enable the IPv4 source guard function on an interface before the interface can obtain dynamic IPv4 binding entries and use static and dynamic IPv4 binding entries to filter packets or help other modules to provide security services. 162

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

162
For information about ARP detection, see "
Configuring ARP attack protection
."
Dynamic IPv4 source binding entries
IP source guard can automatically obtain user information from other modules to generate IPv4 binding
entries. On interfaces configured with the dynamic IPv4 source guard function, IP source guard
cooperates with different modules to generate IPv4 binding entries dynamically:
On an Ethernet port, IP source guard can cooperate with DHCP snooping, obtain the DHCP
snooping entries generated when hosts dynamically obtain IP addresses, and generate IPv4
binding entries accordingly to filter packets.
On a VLAN interface, IP source guard can cooperate with the DHCP relay agent, obtain the DHCP
relay entries generated when hosts obtain IP addresses across subnets, and generate IPv4 binding
entries accordingly to filter packets.
On a VLAN interface, IP source guard can also cooperate with the DHCP server. It generates
dynamic binding entries according to the user information recorded by the DHCP server during IP
address allocation. Such binding entries do not filter packets directly but help other modules (such
as the ARP detection module) to provide security services.
For information about DHCP snooping, DHCP relay, and DHCP server see
Layer 3—IP Services
Configuration Guide
.
IP source guard configuration task list
To configure IPv4 source guard, perform the following tasks:
Tasks at a glance
(Required.)
Enabling IPv4 source guard on an interface
(Optional.)
Configuring a static IPv4 source guard binding entry on an interface
To configure IPv6 source guard, perform the following tasks:
Tasks at a glance
(Required.)
Enabling IPv6 source guard on an interface
(Optional.)
Configuring a static IPv6 source guard binding entry on an interface
Configuring the IPv4 source guard function
You cannot configure the IPv4 source guard function on a service loopback interface. If IPv4 source
guard is enabled on an interface, you cannot assign the interface to a service loopback group.
Enabling IPv4 source guard on an interface
You must first enable the IPv4 source guard function on an interface before the interface can obtain
dynamic IPv4 binding entries and use static and dynamic IPv4 binding entries to filter packets or help
other modules to provide security services.