barox Kommunikation 405.2.3. IP Source GuardDeployment and ConfigurationAn extended function for the protection of the terminal side is provided by using the IP SourceGuard function. This function links the predefined static IP address of the connected devices withthe examination of the MAC addresses of the source terminal devices. As shown in the followingscreenshot this function is generally activated and can be adjusted on a per-port basis.Once this function is switched on the configuration can be effected using static entries as shownbelow.The use of IP Source Guard enables the extended protection function by securing the ports bymeans of the MAC and IP address. Compared to port security, where static MAC address entriesper port prevent a potential attack, IP Source Guard provides the verification of the IP address ofthe connected device using static entries. The switch will block the port‘s network communicationwhere the connected device does not comply with the allocated MAC and IP address. Thismeans, that the attacker must know the MAC address and IP address of the device for gaini ngaccess to the network.