LogoLogo
Release NoteMicrositeWhite PapersCloud License
Cloud User Manual
Cloud User Manual
  • What is EnGenius Cloud?
  • Getting Started
    • Signing Up
    • Logging On
    • Registering Devices to Organization
    • Assigning Devices to Network
    • Device Setup
      • QIG
      • Troubleshooting ECW AP
        • LED Status
        • Default SSIDs
        • Login to Local Access Page
      • Label information
  • Working with Organization Trees
    • Organization
    • Hierarchy View
    • Network
  • Managing Devices
    • Managing Camera
      • Recording Playback and smart Motion Search
      • Configure and Check Camera Details
        • Camera AI settings
        • Region & Cross Lines
      • Video Walls
      • AI-Powered Search
    • Managing Gateway
      • Configure and Check Gateway Details
      • VPN Status
    • Managing Access Points
      • Diag Tools
      • Configure and Check AP Details
      • AirGuard
    • Managing Switches
      • Diag Tools
      • PoE scheduling
      • Getting Switch Analytics
      • PD/Auto-Cam Lifeguard
      • VLANs
      • Mirror
      • Link Aggregation
    • Managing PDU
      • Outlet Summary
      • Outlet Scheduling
      • Outlet AutoReboot
      • Alerts
      • Diag Tool
      • LCD Panel
    • Managing Clients
      • Client Timeline
    • Device Map Location
    • Floor Plans
    • Topology
  • Configuring Networks
    • Configuring Access Points
      • Configuring SSIDs
        • 802.11 Settings
        • Configuring Security
        • SmartCasting
        • Client IP Addressing
        • Dynamic VLAN Pooling
        • Advanced Settings
        • QoS
        • Captive Portal
        • LDAP server
        • Active Directory
        • Azure AD
        • Voucher Service
        • Configuring Splash Page
        • Access control
        • Clone SSID
        • Hotspot 2.0
        • Application Control
        • Examples
      • Configuring Radio
      • Configuring Cloud RADIUS
      • Configuring MyPSK
      • Configuring VLAN
    • Configuring Switch
      • System & Protocols
      • Templates
    • Configuring Gateway
      • Configuring Interface
        • WAN
        • LAN
        • Static Route
        • Policy Route
      • Configuring Site to Site VPN
      • Configuring Client VPN
        • VPN settings for IOS
        • VPN settings for Mac OS
        • VPN settings for Android
        • VPN settings for Windows 10
      • Configure ESG VPN Users
      • Configuring Firewall
    • Configuring PDU
      • Template
    • Configuring Camera
      • Quality & Retention
    • Firmware Upgrade
    • General Settings
    • Client Access Control
  • Analytics
    • Device Events
    • System Events
    • Config Logs
  • MSP Portal
    • Dashboard
    • Teams
    • Inventory & License
    • Clone Org & Networks
  • Managing Organizations
    • Managing Device Inventory and License
    • Privacy
    • Backup & Restore
      • Configuration Template
  • Managing Team Members
    • Roles and Permissions
  • Notification & Alerts
    • Notification Center
    • Configuring Alert Settings
  • Mobile App
  • Get Remote Support
  • Security
    • Two Factor Authentication
    • RadSec Certificate
  • Report
  • Appendix
    • Access Point LED Behavior
    • ESG LED Behavior
    • SSID Troubleshooting Naming Rules
    • Firewall rules
      • Global Site
      • Japan Site
  • Configuration Guide
    • SAML SSO with ADFS
Powered by GitBook
On this page
  • Protected Switch Port List
  • IMPB Client List
  • How to Configure

Was this helpful?

Export as PDF
  1. Configuring Networks
  2. Client Access Control

IP Mac Port Binding

Last updated 4 months ago

Was this helpful?

IP-MAC-Port Binding (IMPB) is a strict way to control your wired clients, protecting them from hacker attacks. Malicious users usually use ARP spoofing or a man-in-the-middle attack to change or steal important data transmitted among your network. IMPB helps to verify the correctness of network packets from authorized clients and forbid those packets that have been changed by hackers.

Each IMPB authorized client must have a valid combination of IP address, MAC address, and switch port connection. Any packet transmission on switches that does not match all these three elements will be treated as an illegal packet and dropped.

IMPB is a function that is suitable for applications that require highly secured networks, such as an ISP, government, or military.

Protected Switch Port List

When a switch port is added to the list, the port will be added to the DHCP snooping trusted port, and IPSG will be enabled on that port as well. When a switch has no port in the list, IPSG will be disabled.

IMPB Client List

IMPB client list controls the permission on all protected ports. Once an IP/MAC/Port combination has been added to the list, the corresponding switch will increase an IPSG rule locally to permit the device.

How to Configure

There are two ways to configure IP-MAC-Port Binding for clients.

If you'd like to bind an existing client, go to Manage > Clients > Wired Clients and use IMPB action to bind it (them).

If you'd like to bind clients that do not exist in the wired client list. Go to Configure > Client Access Control > IP-MAC-Port Binding, adding a switch/port that you'd like to do IMPB to the Protected Switch Port list, and then add the client to the IMPB Client List to bind it to the corresponding port.

Must know

IMPB is supported by ECS v1.2.105(L2+)/v2.2.35(L3) or later version. Switch-Lite (ECS-L) and Switch Extender (EXT) do not support IMPB..

IMPB is a feature that requires ProSW license.

Use wired client list to bind single device
Use wired client list to bind multiple devices
Manually bind clients in IMPB page