ZXR10-IP-SOURCE-GUARD-MIB

MIB Reference — IPNetwork Monitor · Updated September 09, 2026

All MIBsZXR10-IP-SOURCE-GUARD-MIB

Organization: ZTE Corporation

Last Updated: 2012-12-25

Category: ZTE ZXR10 Security and Access Control

Description: Manages ZTE ZXR10 IP Source Guard bindings to prevent IP spoofing by validating source addresses on switch ports.

Start monitoring vendor-neutral, standards-based MIB, any SNMPv3-capable network device (SNMP engine identity/boot/clock status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

What Is ZXR10-IP-SOURCE-GUARD-MIB?

ZXR10-IP-SOURCE-GUARD-MIB implements IP Source Guard on ZTE ZXR10 switches, validating that traffic entering a port uses only a bound, allowed source IP (and typically MAC) address, most often derived from DHCP snooping bindings, in order to prevent IP address spoofing. It exposes per-port binding and enable-state configuration. It is a security-configuration MIB, useful for confirming that a port's guard is correctly enforcing its expected address bindings rather than for reporting hardware health, though guard violations are themselves a security-relevant event worth monitoring. It relies on and typically complements DHCP snooping binding data derived from the DHCP protocol (RFC 2131). It is typically deployed on ZXR10 access/aggregation switches to prevent IP spoofing attacks originating from subscriber or LAN-facing ports. Engineers can download the ZXR10-IP-SOURCE-GUARD-MIB file directly to load it into their MIB browser.

IPNetwork Monitor allows you to monitor SNMP objects defined in ZXR10-IP-SOURCE-GUARD-MIB. Use the built-in SNMP Monitoring Browser to explore available variables, view their current values and descriptions, and select the objects you want to monitor. You can then create SNMP monitors, configure thresholds, and receive alerts when monitored values change.

Supported Devices

  • ZTE ZXR10 switch

Monitoring Examples

No specific object names were present in the source, so the following scenario is inferred from module_desc: an operator would check the source-guard binding table for a given port to confirm the bound IP/MAC pair matches the subscriber's DHCP-leased address. Traffic being dropped due to a source-guard violation would show up as a mismatch between the observed source address and the bound entry, indicating either a spoofing attempt or a stale binding following an IP address renewal.

What Can Be Monitored

  • IP source guard enable state per port
  • bound IP/MAC address entries
  • source-guard violation/drop indication
Imported Objects

From SNMPv2-SMI

MODULE-IDENTITY
OBJECT-TYPE
enterprises

From SNMPv2-TC

DisplayString
RowStatus
OIDs

RFC description

Configures IP data filtering policies and IP source guard enforcement on ZTE ZXR10 devices.

Start monitoring ZTE ZXR10 switch (per-port IP-source-binding enforcement config status) with a free 30-day trial of IPNetwork Monitor. Import MIBs, browse SNMP OIDs, create custom SNMP monitors, configure alerts, and monitor any SNMP-enabled network device from a single console.

Download ZXR10-IP-SOURCE-GUARD-MIB