Configuring Ip-Mac Binding To Prevent Spoofing - Cisco ISA550 Administration Manual

Isa500 series integrated security appliances
Hide thumbs Also See for ISA550:
Table of Contents

Advertisement

Firewall

Configuring IP-MAC Binding to Prevent Spoofing

Configuring IP-MAC Binding to Prevent Spoofing
NOTE
STEP 1
STEP 2
STEP 3
STEP 4
STEP 5
Cisco ISA500 Series Integrated Security Appliances Administration Guide
IP-MAC Binding allows you to bind an IP address to a MAC address and
vice-versa. It only allows traffic when the host IP address matches a specified
MAC address. By requiring the gateway to validate the source traffic's IP address
with the unique MAC address of device, this ensures that traffic from the specified
IP address is not spoofed. If a violation (the traffic's source IP address doesn't
match the expected MAC address having the same IP address), the packets will
be dropped and can be logged for diagnosis.
Up to 100 IP-MAC binding rules can be configured on the security appliance.
Click Firewall > MAC Filtering > IP - MAC Binding Rules.
The IP - MAC Binding Rules window opens.
To add an IP-MAC binding rule, click Add.
Other options: To edit an entry, click the Edit (pencil) icon. To delete an entry, click
the Delete (x) icon. To delete multiple entries, check them and click Delete.
The IP&MAC Binding Rule - Add/Edit window opens.
Enter the following information:
Name: Enter the name for the IP-MAC binding rule.
MAC Address: Choose an existing MAC address object. If the MAC address
object that you want is not in the list, choose Create a new address to add
a new MAC address object. To maintain the MAC address objects, go to the
Networking > Address Management page. See
page
173.
IP Address: Choose an existing IP address object that you want to bind with
the selected MAC address. If the IP address object that you want is not in the
list, choose Create a new address to add a new IP address object. To
maintain the IP address objects, go to the Networking > Address
Management page. See
Log Dropped Packets: Choose Enable to log all packets that are dropped.
Otherwise, choose Disable.
Click OK to save your settings.
Click Save to apply your settings.
Address Management, page
Address Management,
173.
6
238

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Isa550wIsa570Isa570w

Table of Contents