- Community Home
- >
- Networking
- >
- Legacy
- >
- Switches, Hubs, Modems
- >
- IP-MAC binding for static IP hosts
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО04-06-2010 05:01 AM
тАО04-06-2010 05:01 AM
IP-MAC binding for static IP hosts
Are there any working configuration?
THANKS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО04-06-2010 04:31 PM
тАО04-06-2010 04:31 PM
Re: IP-MAC binding for static IP hosts
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО04-06-2010 10:23 PM
тАО04-06-2010 10:23 PM
Re: IP-MAC binding for static IP hosts
I give static IP adresses manually to the hosts according to their mac addresses.
I dont know on which port of the switch hosts are connected.
I want to lock arp cache of the switch statically.
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО04-07-2010 08:35 AM
тАО04-07-2010 08:35 AM
Re: IP-MAC binding for static IP hosts
When you say you are assigning IP addresses statically based on their MAC addresses, I presume you mean you are using DHCP where the DHCP server is configured to give-out specific IP addresses to specific MAC addresses yes?
More generally, all locking an ARP cache does is say that a given IP address is associated with a given MAC address. That would preclude having that same IP address assigned to a different MAC address from "working" but it would not preclude a second IP address becoming associated with that first MAC address. You would have to disable ARP entirely on all the hosts in your network to be able to prevent them from learning new IPs associated with existing MACs. Even if you could block ARP traffic at the switch, you would still need to populate all your hosts with static ARP tables, and the means by which you might (or might not) be able to do that will vary with each distict host OS.
And, if the users of those hosts already had enough priviledges on those host OSes to try to assign their own IPs, they would have enough priviledges to enter new IP-MAC translations into their local ARP caches.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО04-07-2010 10:26 AM
тАО04-07-2010 10:26 AM
Re: IP-MAC binding for static IP hosts
DHCP Snooping
ARP Protection
You mainly want the ARP Protection feature but you must also enable DHCP Snooping for AP to work (even if you are not doing DHCP).
AP tells the switch to only allow specific IP-to-MAC pairs to be able to pass any traffic through it.
If you are doing DHCP on clients with reservations, then the switch will learn these mappings. If you are doing static assigned IP's on clients, you can enter a table of static mappings into the switch.
These features also lock the IP-MAC pairs at the port/vlan they are coming into and only allow that traffic to flow.
The downside, anyone could Wireshark the network, listen from broadcasts, glean the IP-MAC pairs, and spoof them, and they would look legit.
Basically, to control changes at the client, you must control ADMIN access on the client (as mentioned in a port here). This type of control can't totally be done in the infrastructure, but you can contain some of the allowed traffic.
You could also implement 802.1X/PCM/IDM and build policies that force IP, MAC, machine specific, uid, network location (switch/port) and even time-of-day/day-of-week tests, and if everything passes the test, allow that traffic.
hth...Jeff
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО04-11-2010 01:34 PM
тАО04-11-2010 01:34 PM
Re: IP-MAC binding for static IP hosts
Giving the following error?
What is this limit?
SWITCH(config)# ip source-lockdown Trk1
Cannot enable Dynamic IP Lockdown on port(s)Trk1, manual binding limits are exceeded.
Thanks?