ZyXEL ES-2108PWR User Guide - Page 169

ARP Inspection Status

Page 169 highlights

Chapter 21 IP Source Guard 21.4 ARP Inspection Status Use this screen to look at the current list of MAC address filters that were created because the Switch identified an unauthorized ARP packet. When the Switch identifies an unauthorized ARP packet, it automatically creates a MAC address filter to block traffic from the source MAC address and source VLAN ID of the unauthorized ARP packet. To open this screen, click Advanced Application > IP Source Guard > ARP Inspection. Figure 93 Advanced Application > IP Source Guard > ARP Inspection: Status The following table describes the labels in this screen. Table 59 Advanced Application > IP Source Guard > ARP Inspection: Status LABEL DESCRIPTION Total number of filters This field displays the current number of MAC address filters that were created because the Switch identified unauthorized ARP packets. Index This field displays a sequential number for each MAC address filter. MAC Address This field displays the source MAC address in the MAC address filter. VID This field displays the source VLAN ID in the MAC address filter. Port This field displays the source port of the discarded ARP packet. Expiry (sec) This field displays how long (in seconds) the MAC address filter remains in the Switch. You can also delete the record manually (Delete). Reason This field displays the reason the ARP packet was discarded. MAC+VLAN: The MAC address and VLAN ID were not in the binding table. IP: The MAC address and VLAN ID were in the binding table, but the IP address was not valid. Port: The MAC address, VLAN ID, and IP address were in the binding table, but the port number was not valid. Delete Select this, and click Delete to remove the specified entry. Delete Click this to remove the selected entries. Cancel Click this to clear the Delete check boxes above. 21.4.1 ARP Inspection Log Status Use this screen to look at log messages that were generated by ARP packets and that have not been sent to the syslog server yet. To open this screen, click Advanced Application > IP Source Guard > ARP Inspection > Log Status. ES-2108 Series User's Guide 169

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284

Chapter 21 IP Source Guard
ES-2108 Series User’s Guide
169
21.4
ARP Inspection Status
Use this screen to look at the current list of MAC address filters that were created because the
Switch identified an unauthorized ARP packet. When the Switch identifies an unauthorized
ARP packet, it automatically creates a MAC address filter to block traffic from the source
MAC address and source VLAN ID of the unauthorized ARP packet. To open this screen,
click
Advanced Application > IP Source Guard > ARP Inspection
.
Figure 93
Advanced Application > IP Source Guard > ARP Inspection: Status
The following table describes the labels in this screen.
21.4.1
ARP Inspection Log Status
Use this screen to look at log messages that were generated by ARP packets and that have not
been sent to the syslog server yet. To open this screen, click
Advanced Application > IP
Source Guard > ARP Inspection > Log Status
.
Table 59
Advanced Application > IP Source Guard > ARP Inspection: Status
LABEL
DESCRIPTION
Total number of filters
This field displays the current number of MAC address filters that were
created because the Switch identified unauthorized ARP packets.
Index
This field displays a sequential number for each MAC address filter.
MAC Address
This field displays the source MAC address in the MAC address filter.
VID
This field displays the source VLAN ID in the MAC address filter.
Port
This field displays the source port of the discarded ARP packet.
Expiry (sec)
This field displays how long (in seconds) the MAC address filter remains in
the Switch. You can also delete the record manually (
Delete
).
Reason
This field displays the reason the ARP packet was discarded.
MAC+VLAN
: The MAC address and VLAN ID were not in the binding
table.
IP
: The MAC address and VLAN ID were in the binding table, but the IP
address was not valid.
Port
: The MAC address, VLAN ID, and IP address were in the binding
table, but the port number was not valid.
Delete
Select this, and click
Delete
to remove the specified entry.
Delete
Click this to remove the selected entries.
Cancel
Click this to clear the
Delete
check boxes above.