<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dynamic IP Lockdown in Switches, Hubs, and Modems</title>
    <link>https://community.hpe.com/t5/switches-hubs-and-modems/dynamic-ip-lockdown/m-p/5240384#M29567</link>
    <description>Yes, Dynamic IP Lockdown works exaclty how you described it and it is an addon to the arp protection feature. It checks each IPv4 packet received from a port (wirespeed!) so, if this feature is enabled on a port, then it is not possible to steal IP+MAC combination by using a computer connected to that port.&lt;BR /&gt;&lt;BR /&gt;There is no age-out mechanisms. It uses the same database like in the arp-protect feature. Entries can be collected automatically (dhcp snooping) or inserted manually:&lt;BR /&gt; ip source-binding &lt;VLAN&gt; &lt;IP&gt; &lt;MAC&gt; &lt;PORT&gt;&lt;BR /&gt;&lt;BR /&gt;So, it is possible to use it also when it is not feasible to require a dhcp assigment (think of servers).&lt;/PORT&gt;&lt;/MAC&gt;&lt;/IP&gt;&lt;/VLAN&gt;</description>
    <pubDate>Tue, 18 May 2010 17:59:25 GMT</pubDate>
    <dc:creator>Krzysztof Oledzki</dc:creator>
    <dc:date>2010-05-18T17:59:25Z</dc:date>
    <item>
      <title>Dynamic IP Lockdown</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/dynamic-ip-lockdown/m-p/5240383#M29566</link>
      <description>Hi all,&lt;BR /&gt;&lt;BR /&gt;The company I work for at the moment is considering LAN security.&lt;BR /&gt;There are several options to choose from.&lt;BR /&gt;&lt;BR /&gt;One of the options I consider to implement is Dynamic IP lockdown (besides DHCP snooping protection and ARP protection).&lt;BR /&gt;&lt;BR /&gt;Am I right that dynamic IP lockdown:&lt;BR /&gt;1. Locks an IP and MAC address combination to a port&lt;BR /&gt;2. Prevents "using" a e.g workstations IP and MAc-address combination even when a ws is turned off.&lt;BR /&gt;&lt;BR /&gt;Another question I have:&lt;BR /&gt;3. What age-out mechanism is used (mac-age-out?)&lt;BR /&gt;&lt;BR /&gt;TIA&lt;BR /&gt;&lt;BR /&gt;Jaap</description>
      <pubDate>Tue, 18 May 2010 14:21:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/dynamic-ip-lockdown/m-p/5240383#M29566</guid>
      <dc:creator>Jaap Laaij</dc:creator>
      <dc:date>2010-05-18T14:21:40Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic IP Lockdown</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/dynamic-ip-lockdown/m-p/5240384#M29567</link>
      <description>Yes, Dynamic IP Lockdown works exaclty how you described it and it is an addon to the arp protection feature. It checks each IPv4 packet received from a port (wirespeed!) so, if this feature is enabled on a port, then it is not possible to steal IP+MAC combination by using a computer connected to that port.&lt;BR /&gt;&lt;BR /&gt;There is no age-out mechanisms. It uses the same database like in the arp-protect feature. Entries can be collected automatically (dhcp snooping) or inserted manually:&lt;BR /&gt; ip source-binding &lt;VLAN&gt; &lt;IP&gt; &lt;MAC&gt; &lt;PORT&gt;&lt;BR /&gt;&lt;BR /&gt;So, it is possible to use it also when it is not feasible to require a dhcp assigment (think of servers).&lt;/PORT&gt;&lt;/MAC&gt;&lt;/IP&gt;&lt;/VLAN&gt;</description>
      <pubDate>Tue, 18 May 2010 17:59:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/dynamic-ip-lockdown/m-p/5240384#M29567</guid>
      <dc:creator>Krzysztof Oledzki</dc:creator>
      <dc:date>2010-05-18T17:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic IP Lockdown</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/dynamic-ip-lockdown/m-p/5240385#M29568</link>
      <description>Hi Krzysztof,&lt;BR /&gt;&lt;BR /&gt;Thanks for your answer.&lt;BR /&gt;This will help me convince my manager :).&lt;BR /&gt;&lt;BR /&gt;Greetz Jaap&lt;BR /&gt;(A late response because of the "black-out")</description>
      <pubDate>Tue, 25 May 2010 10:18:23 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/dynamic-ip-lockdown/m-p/5240385#M29568</guid>
      <dc:creator>Jaap Laaij</dc:creator>
      <dc:date>2010-05-25T10:18:23Z</dc:date>
    </item>
  </channel>
</rss>

