Security Configuration
ACL Configuration
Communication between information points and communication between internal and external networks are essential business requirements in enterprise networks. To ensure the security of the internal network, it is necessary to use security policies to ensure that unauthorized users can only access specific network resources.
ARP Attack Detection Configuration
ARP attack detection is one of the common methods to prevent ARP spoofing. It is used to detect ARP packets based on DHCP Snooping and static binding entries on access devices, preventing ARP attacks from unauthorized users.
IPSG Configuration
IP Source Guard (IPSG) is a defense mechanism against IP address spoofing attacks. It checks whether a user on a specific VLAN interface is a legitimate user based on the source IP address and source MAC address in the IP packet.
SAVI Configuration
SAVI (Source Address Validation Improvement) is a mechanism used on access devices to validate the authenticity of IPv6 Neighbor Discovery (ND) protocol packets. It is based on ND Snooping, DHCP Snooping, and static binding entries, and it helps prevent unauthorized packets from entering the internal network.
RA Guard Configuration
RA Guard functionality is used on Layer 2 access devices to prevent Router Advertisement (RA) message spoofing attacks. When a Layer 2 access device receives an RA message with a unicast or multicast MAC address, the RA Guard functionality processes the RA message as follows If the port is not configured with a port role, the RA message is directly forwarded.