Security Configuration
ARP Attack Detection Configuration
ARP attack detection is one of the common methods to prevent ARP spoofing. It is used to detect ARP packets based on DHCP Snooping and static binding entries on access devices, preventing ARP attacks from unauthorized users.
IPSG Configuration
IP Source Guard (IPSG) is a defense mechanism against IP address spoofing attacks. It checks whether a user on a specific VLAN interface is a legitimate user based on the source IP address and source MAC address in the IP packet.
SAVI Configuration
SAVI (Source Address Validation Improvement) is a mechanism used on access devices to validate the authenticity of IPv6 Neighbor Discovery (ND) protocol packets. It is based on ND Snooping, DHCP Snooping, and static binding entries, and it helps prevent unauthorized packets from entering the internal network.
RA Guard Configuration
RA Guard functionality is used on Layer 2 access devices to prevent Router Advertisement (RA) message spoofing attacks. When a Layer 2 access device receives an RA message with a unicast or multicast MAC address, the RA Guard functionality processes the RA message as follows If the port is not configured with a port role, the RA message is directly forwarded.
Storm Suppression Configuration
Storm suppression is a security technique used to control broadcast, known multicast, unknown unicast, and unknown multicast packets, preventing these four types of packets from causing broadcast storms. After configuring broadcast, known multicast, unknown unicast, and unknown multicast storm suppression on a port, when the traffic of broadcast, known multicast, unknown unicast, or unknown multicast packets on the port exceeds the threshold set by the user, the port will discard the packets that exceed the traffic threshold.
ACL Configuration
Communication between information points and communication between internal and external networks are essential business requirements in enterprise networks. To ensure the security of the internal network, it is necessary to use security policies to ensure that unauthorized users can only access specific network resources.