Tp-Link T2600G-28MPS (TL-SG3424P) Руководство пользователя онлайн [305/379] 174195

Tp-Link T2600G-28MPS (TL-SG3424P) Руководство пользователя онлайн [305/379] 174195
Generally, the ND detection feature uses the entries in the IPv6-MAC binding table to verify the
packets received on the untrusted ports, thus filtering the forged ND packets and keeping out
the attacks.
1. ND packets received on the ND-trusted port will not be checked.
2. RS/NS packets with their source IPv6 address unspecified will not be checked.
3. RA/RR packets received on the ND-untrusted port will be discarded directly; the other ND
packets received on the ND-untrusted port will be checked.
a) Source MAC consistence check. If the RS/NS packet’s source MAC address in the
Ethernet frame header is different from that carried in the source layer address option,
the RS/NS packet will be discarded.
b) IPv6-MAC binding check. Look up the IPv6-MAC binding table to compare the IPv6
address, MAC address, VLAN ID and receiving port between the entry and the ND packet.
If a match is found, the ND packet is considered legal and forwarded; if no match is found,
the ND packet is considered illegal and discarded directly.
Choose the menu Network Security→ND Detection→ND Detection to load the following
page.
Figure 14-22 ND Detection
ND Detection
ND Detection:
Enable/Disable the ND Detection function.
VLAN ID:
Enter the VLAN ID in which you want to enable/
disable the ND
Detection function.
VLAN Configuration
Display:
Display the VLANs with ND detection function enabled.
Trusted Port
293

Содержание

Скачать