ProSafe Wireless-N VPN Firewall SRXN3205 Reference Manual
5-22
Firewall Security and Content Filtering
v1.0, October 2008
3.
Click the
Yes
radio button to enable Source MAC Filtering.
IP/MAC Bind Table lists the currently defined IP/MAC Bind rules:
–
Name: Displays the user-defined name for this rule.
–
MAC Addresses: Displays the MAC Addresses for this rule.
–
IP Addresses: Displays the IP Addresses for this rule.
–
Log Dropped Packets: Displays logging option for this rule.
To remove an entry from the table, select the IP/MAC Bind entry and click Delete. To edit an
entry, click Edit adjacent to the entry.
Add IP/MAC Bind Rule
–
Name: Specify easily identifiable name for this rule.
–
MAC Address: Specify the MAC Address for this rule.
–
IP Addresses: Specify the IP Address for this rule.
–
Log Dropped Packets: Specify Logging option for this rule.
Edit IP/MAC Bind Rule: the following fields of an existing IP/MAC Bind rule can be
modified:
–
MAC Address: Specify the MAC Address for this rule.
–
IP Addresses: Specify the IP Address for this rule.
–
Log Dropped Packets: Specify Logging option for this rule.
Example: If three computers are on the LAN with the following setup:
Host1 -- MAC address(00:01:02:03:04:05) & IP address(192.168.10.10)
Host2 -- MAC address(00:01:02:03:04:06) & IP address(192.168.10.11)
Host3 -- MAC address(00:01:02:03:04:07) & IP address(192.168.10.12)
All the above host entries are added in IP/MAC Binding table. The scenario for the above hosts are
as such:
Host1 -- Matching IP & MAC address in IP/MAC Table.
Host2 -- Matching IP but inconsistent MAC address in IP/MAC Table.
Host3 -- Matching MAC but inconsistent IP address in IP/MAC Table.
The router will block the traffic coming from Host2 & Host3 but allow the traffic coming from
Host1 to any external network. Total count of dropped packets will be displayed.