ZyXEL GS1910-24 User Guide - Page 45

Enabling Port Isolation

Page 45 highlights

5 Click Save to save the settings to the Switch. Chapter 5 Tutorials 5.6.2 Enabling Port Isolation Follow the steps below to configure port isolation. 1 Click Configuration > Private VLANs > Port Isolation. 2 Select the check boxes of ports 2, 3 and 4, and click Save to add them to the isolated port list so that they cannot send traffic to each other. From port 2, 3, or 4, you should be able to access the device that attaches to port 25, such as a server or default gateway. 5.7 How to Use IP Source Guard and DHCP Snooping to Prevent Spoofed Traffic IP source guard uses a binding table to allow or block IP traffic in your network. When the Switch receives an IP packet, it looks up the appropriate MAC address, VLAN ID, IP address, and port number in the binding table. If there is a binding, the Switch forwards the packet. If there is not a binding, the Switch discards the packet. The Switch builds the binding table by snooping DHCP packets (dynamic bindings) and from information provided manually by administrators (static bindings). Use DHCP snooping to filter unauthorized DHCP packets on the network and to build the binding table dynamically. This can prevent clients from getting IP addresses from unauthorized DHCP servers. GS1910/XGS1910 Series User's Guide 45

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76

Chapter 5 Tutorials
GS1910/XGS1910 Series User’s Guide
45
5
Click
Save
to save the settings to the Switch.
5.6.2
Enabling Port Isolation
Follow the steps below to configure port isolation.
1
Click
Configuration > Private VLANs > Port Isolation
.
2
Select the check boxes of ports 2, 3 and 4, and click
Save
to add them to the isolated port list so
that they cannot send traffic to each other.
From port 2, 3, or 4, you should be able to access the device that attaches to port 25, such as a
server or default gateway.
5.7
How to Use IP Source Guard and DHCP Snooping to
Prevent Spoofed Traffic
IP source guard uses a binding table to allow or block IP traffic in your network. When the Switch
receives an IP packet, it looks up the appropriate MAC address, VLAN ID, IP address, and port
number in the binding table. If there is a binding, the Switch forwards the packet. If there is not a
binding, the Switch discards the packet.
The Switch builds the binding table by snooping DHCP packets (dynamic bindings) and from
information provided manually by administrators (static bindings).
Use DHCP snooping to filter unauthorized DHCP packets on the network and to build the binding
table dynamically. This can prevent clients from getting IP addresses from unauthorized DHCP
servers.