Web Management Guide-R04

Table Of Contents
Chapter 12
| Security Measures
IPv4 Source Guard
– 388 –
SIP-MAC – Enables traffic filtering based on IPv4 addresses and
corresponding MAC addresses stored in the binding table.
Filter Table – Sets the source guard learning model to search for addresses in
the ACL binding table or the MAC address binding table. (Default: ACL binding
table)
Max Binding Entry – The maximum number of entries that can be bound to an
interface. (ACL Table: 1-32, default: 16; MAC Table: 1-32, default: 16)
This parameter sets the maximum number of address entries that can be
mapped to an interface in the binding table, including both dynamic entries
discovered by DHCP snooping (see “DHCPv4 Snooping” on page 368) and
static entries set by IP source guard (see “Configuring Static Bindings for IPv4
Source Guard” on page 389).
The maximum binding for ACL mode restricts the number of “active” entries
per port. If binding entries exceed the maximum number in IPv4 source guard,
only the maximum number of binding entries will be set. Dynamic binding
entries exceeding the maximum number will be created but will not be active.
The maximum binding for MAC mode restricts the number of MAC addresses
learned per port. Authenticated IP traffic with different source MAC addresses
cannot be learned if it would exceed this maximum number.
Web Interface
To set the IP Source Guard filter for ports:
1. Click Security, IP Source Guard, Port Configuration.
2. Set the required filtering type for each port.
3. Click Apply
Figure 240: Setting the Filter Type for IP Source Guard