Cisco Nexus 5000 Series Руководство по конфигурации

Просмотреть онлайн или скачать pdf Руководство по конфигурации для Сетевой маршрутизатор Cisco Nexus 5000 Series. Cisco Nexus 5000 Series 6 страниц. Configuring ip source guard
Также для Cisco Nexus 5000 Series: Примечание к выпуску (26 страниц), Краткое справочное руководство (14 страниц), Примечание к выпуску (26 страниц), Справочное руководство (12 страниц), Руководство по устранению неполадок (8 страниц), Руководство (11 страниц), Руководство (6 страниц), Руководство (7 страниц), Руководство по эксплуатации (45 страниц)

Cisco Nexus 5000 Series Руководство по конфигурации
Configuring IP Source Guard
This chapter describes how to configure IP Source Guard on the Cisco Nexus 5000 Series switch.
This chapter includes the following sections:

Information About IP Source Guard

IP Source Guard is a per-interface traffic filter that permits IP traffic only when the IP address and MAC
address of each packet matches one of two sources of IP and MAC address bindings:
• Entries in the Dynamic Host Configuration Protocol (DHCP) snooping binding table.
• Static IP source entries that you configure.
Filtering on trusted IP and MAC address bindings helps prevent spoofing attacks, in which an attacker uses
the IP address of a valid host to gain unauthorized network access. To circumvent IP Source Guard, an attacker
would have to spoof both the IP address and the MAC address of a valid host.
You can enable IP Source Guard on Layer 2 interfaces that are not trusted by DHCP snooping. IP Source
Guard supports interfaces that are configured to operate in access mode and trunk mode. When you initially
enable IP Source Guard, all inbound IP traffic on the interface is blocked except for the following:
• DHCP packets, which DHCP snooping inspects and then forwards or drops, depending upon the results
of inspecting the packet.
Cisco Nexus 5000 Series NX-OS Security Configuration Guide, Release 5.0(3)N1(1)
1