Web Management Guide-R05

Table Of Contents
Chapter 12
| Security Measures
IPv4 Source Guard
– 321 –
SIP-MAC – Enables traffic filtering based on IP addresses and
corresponding MAC addresses stored in the binding table.
Filter Table – Sets the source guard learning model to search for addresses in
the ACL binding table or the MAC address binding table. (Default: ACL binding
table)
Max Binding Entry – The maximum number of entries that can be bound to an
interface. (ACL Table: 1-5, default: 5; MAC Table: 1-1024, default: 1024)
This parameter sets the maximum number of address entries that can be
mapped to an interface in the binding table, including both dynamic entries
discovered by DHCP snooping (see “DHCP Snooping” on page 311) and static
entries set by IP source guard (see Configuring Static Bindings for IPv4 Source
Guard” on page 321).
Web Interface
To set the IP Source Guard filter for ports:
1. Click Security, IP Source Guard, General.
2. Set the required filtering type, set the table type to use ACL or MAC address
binding, and then set the maximum binding entries for each port.
3. Click Apply.
Figure 200: Setting the Filter Type for IPv4 Source Guard
Configuring
Static Bindings
forIPv4Source Guard
Use the Security > IP Source Guard > Static Binding (Configure ACL Table and
Configure MAC Table) pages to bind a static address to a port. Table entries include
a MAC address, IP address, lease time, entry type (Static, Dynamic), VLAN identifier,
and port identifier. All static entries are configured with an infinite lease time,
which is indicated with a value of zero in the table.
Command Usage
Table entries include a MAC address, IP address, lease time, entry type (Static-IP-
SG-Binding, Dynamic-DHCP-Binding), VLAN identifier, and port identifier.
Static addresses entered in the source guard binding table are automatically
configured with an infinite lease time.