| поискавой системы для электроныых деталей |
|
VSC7440 датащи(PDF) 151 Page - Microsemi Corporation |
|
|
|||||||||||||||||||||||||||||
VSC7440 датащи(HTML) 151 Page - Microsemi Corporation |
|
151 / 444 page ![]() Functional Descriptions VMDS-10492 VSC7440 Datasheet Revision 4.2 134 3.19 IP Processing This section provides information about IP routing and IP security checks. The configuration parameters for IP routing are located within the ANA_L3 configuration target. Each frame is subject to two lookups in VCAP LPM. One lookup is used for looking up SIP, and the other lookup is used for looking up DIP or DIP+SIP (for IP multicast frames). 3.19.1 IP Source/Destination Guard For security purposes, the device can be configured to identify specific combinations of the following information and apply security rules based on that information. • (SMAC, SIP) or (VMID, SIP) • (DMAC, DIP) or (VMID, DIP) The VCAP LPM and ARP table in ANA_L3 are used to perform matching. The result of the matching is available for security rules in ANA_ACL through the following VCAP fields: • L3_SMAC_SIP_MATCH. Set to 1 if (VMID, SIP) and/or (SMAC, SIP) match was found. • L3_DMAC_DIP_MATCH. Set to 1 if (VMID, DIP) and/or (DMAC, DIP) match was found. IP source/destination guard check can be enabled per port using COMMON:SIP_SECURE_ENA and COMMON:DIP_SECURE_ENA. When enabled, the frame’s DIP and the frame’s SIP are each looked up in VCAP LPM. The associated VCAP action provides an index to an ARP Table entry in which the required SMAC/DMAC and/or VMID is configured. The following pseudo code specifies the behavior of the IP Source Guard checks. // Determine value of req.l3_sip_match (available in ANA_ACL as L3_SMAC_SIP_MATCH) if (!req.ip4_avail && !req.ip6_avail) { req.l3_sip_match = 1; return; } if (csr.sip_cmp_ena(req.port_num)) { req.l3_sip_match = 0; } else { req.l3_sip_match = 1; } if (!LpmHit()) { return; } if (req.ip4_avail) { csr.secur_ip4_lpm_found_sticky = 1; } if (req.ip6_avail) { csr.secur_ip6_lpm_found_sticky = 1; } sip_arp_entry = csr.arp_tbl[sip_lpm_entry.arp_ptr]; if ((sip_arp_entry.secur_match_vmid_ena == 0 || igr_vlan_entry.vmid == sip_arp_entry.arp_vmid) && (sip_arp_entry.secur_match_mac_ena == 0 || req.smac == sip_arp_entry.mac)) { |
|
ссылки URL |
| Вашему бизинису помогли Аллдатащит? [ DONATE ] |
Что такое Аллдатащит | реклама | контакт | Конфиденциальность | Ссылка на техническое описание | обмен ссыками | поиск по производителю All Rights Reserved©Alldatasheet.com |
| Russian : Alldatasheetru.com | Korean : Alldatasheet.co.kr | Spanish : Alldatasheet.es | French : Alldatasheet.fr | Italian : Alldatasheetit.com Portuguese : Alldatasheetpt.com | Polish : Alldatasheet.pl | Vietnamese : Alldatasheet.vn Indian : Alldatasheet.in | Mexican : Alldatasheet.com.mx | British : Alldatasheet.co.uk | New Zealand : Alldatasheet.co.nz |
|
Family Site : ic2ic.com |
icmetro.com |