Zyxel OLT2412 [293/326] Ip and mac anti spoofing

Zyxel OLT2412 [293/326] Ip and mac anti spoofing
OLT2412 User’s Guide 293
CHAPTER 43
IP and MAC Anti-spoofing
43.1 IP and MAC Anti-spoofing Overview
IP and MAC anti-spoofing protection lets you set inclusive or exclusive mode for specified source IP
addresses or MAC addresses. This lets you allow or block packets from specific IP addresses or MAC
addresses on specific ports. Here are some details about setting anti-spoofing entries:
A port’s anti-spoofing entries must all be exclusive or inclusive (not both).
Set up to four entries per port.
You can only apply anti-spoofing settings to subscriber ports.
You can only add a specific MAC address or IP address in one entry on a port. (We do not want
any two entries have confliction.)
The following tables describe the expected result for each type of anti-spoofing entry.
However, if the IP-only entry and the MAC-only entry are both set at one port, the port allows all
DHCP packets.
The OLT forwards packets from source IP addresses or MAC addresses listed in the inclusive entries
and drops others.
Table 170 Results for Inclusive Anti-Spoofing Entries
SETTING RESULT
IP-Only
(Inclusive)
The OLT allows non-IP packets and DHCP, but blocks other IP packets unless the source
IP address is in the list.
MAC-Only
(Inclusive)
The OLT blocks all packets unless the source MAC address is in the list.
IP-MAC
(Inclusive)
The OLT allows non-IP packets and DHCP, but blocks other IP packets unless the source
MAC address and source IP address are in the list.
OUI-MAC
(Inclusive)
The OLT blocks all packets unless the source OUI-MAC is in the list.
Table 171 Results for Exclusive Anti-Spoofing Entries
SETTING RESULT
IP-Only
(Exclusive)
The OLT allows non-IP packets. The OLT also allows IP packets unless the source IP
address is in the list.
MAC-Only
(Exclusive)
The OLT allows all packets unless the source MAC address is in the list.
IP-MAC
(Exclusive)
The OLT allows non-IP packets. The OLT also allows IP packets unless the source MAC
address and source IP address are in the list.

Содержание