Difference between revisions of "Netband Project - IP Source Guard"

From Teknologisk videncenter
Jump to: navigation, search
(Configuration)
(Configuration)
Line 23: Line 23:
 
Source IP address verification
 
Source IP address verification
 
<pre>
 
<pre>
interface FastEthernet0/10
+
interface FastEthernet0/10
 
  ip verify source  
 
  ip verify source  
 
</pre>
 
</pre>

Revision as of 13:12, 14 April 2009

<accesscontrol>NetBand</accesscontrol> This page is part of the Netband Project

  • IP source guard is a security feature that restricts IP traffic on nonrouted, Layer 2 interfaces by filtering traffic based on the DHCP snooping binding database and on manually configured IP source bindings. You can use IP source guard to prevent traffic attacks caused when a host tries to use the IP address of its neighbor.
  • IP source guard is supported only on Layer 2 ports, including access and trunk ports
  • An ACL is applied to the interface, which allows only IP traffic with a source IP address in the IP source binding table and denies all other traffic.
  • Filtering options
    • Source IP address
      • The switch forwards IP traffic when the source IP address matches an entry in the DHCP snooping binding database or a binding in the IP source binding table.
    • Source IP and MAC Address
      • The switch forwards traffic only when the source IP and MAC addresses match an entry in the IP source binding table.
      • Filters both ip and non-ip traffic
      • Port security is used to filter source MAC addresses
      • Is not supported on pvlan


Configuration

Source IP -and Mac address verification

interface FastEthernet0/10
 ip verify source port-security

Source IP address verification

interface FastEthernet0/10
 ip verify source