Netgear SRX5308 Specifications Page 128

  • Download
  • Add to my manuals
  • Print
  • Page
    / 357
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 127
Firewall Protection
128
ProSafe Gigabit Quad WAN SSL VPN Firewall SRX5308
To remove one or more entries from the table:
1. Select the check box to the left of the MAC address that you want to delete, or click the
Select All table button to select all entries.
2. Click the Delete table button.
Set Up IP/MAC Bindings
IP/MAC binding allows you to bind an IP address to a MAC address and vice versa. Some
PCs or devices are configured with static addresses. To prevent users from changing their
static IP addresses, the IP/MAC binding feature needs to be enabled on the VPN firewall. If
the VPN firewall detects packets with a matching IP address but with the inconsistent MAC
address (or vice versa), the packets are dropped. If you have enabled the logging option for
the IP/MAC binding feature, these packets are logged before they are dropped. The VPN
firewall displays the total number of dropped packets that violate either the IP-to-MAC binding
or the MAC-to-IP binding.
Note: You can bind IP addresses to MAC addresses for DHCP assignment
on the LAN Groups submenu. See Manage the Network Database
on page 68.
As an example, assume that three computers on the LAN are set up as follows:
Host1. MAC address (00:01:02:03:04:05) and IP address (192.168.10.10)
Host2. MAC address (00:01:02:03:04:06) and IP address (192.168.10.11)
Host3. MAC address (00:01:02:03:04:07) and IP address (192.168.10.12)
If all of the preceding host entry examples are added to the IP/MAC Bindings table, the
following scenarios indicate the possible outcome.
Host1. Matching IP address and MAC address in the IP/MAC Bindings table.
Host2. Matching IP address but inconsistent MAC address in the IP/MAC Bindings table.
Host3. Matching MAC address but inconsistent IP address in the IP/MAC Bindings table.
In this example, the VPN firewall blocks the traffic coming from Host2 and Host3, but allows
the traffic coming from Host1 to any external network. The total count of dropped packets is
displayed.
To set up IP/MAC bindings:
1. Select Security > Address Filter > IP/MAC Binding. The IP/MAC Binding screen
displays. (See the following figure, which shows one binding in the IP/MAC Binding table
as an example.)
Page view 127
1 2 ... 123 124 125 126 127 128 129 130 131 132 133 ... 356 357

Comments to this Manuals

No comments