![Cisco 350XG series Administration Manual Download Page 436](http://html.mh-extra.com/html/cisco/350xg-series/350xg-series_administration-manual_67491436.webp)
Security
IP Source Guard
Cisco 350XG & 550XG Series 10G Stackable Managed Switches
422
19
IP Source Guard Work Flow
To configure IP Source Guard:
STEP 1
Enable (DHCP Snooping)
STEP 2
Define the VLANs on which DHCP Snooping is enabled in the (DHCP Snooping)
STEP 3
Configure interfaces as trusted or untrusted in the (DHCP Snooping)
page.
STEP 4
Enable IP Source Guard in the (IP Source Guard)
page.
STEP 5
Enable IP Source Guard on the untrusted interfaces as required in the (IP Source
Guard)
STEP 6
View entries to the Binding database in the (IP Source Guard)
page.
Properties
To enable IP Source Guard globally:
STEP 1
Click
Security
>
IP Source Guard
>
Properties
.
STEP 2
Select
Enable
to enable IP Source Guard globally.
STEP 3
Click
Apply
to enable IP Source Guard.
Interface Settings
If IP Source Guard is enabled on an untrusted port/LAG, DHCP packets, allowed
by DHCP Snooping, are transmitted. If source IP address filtering is enabled,
packet transmission is permitted as follows:
•
IPv4 traffic —
Only IPv4 traffic with a source IP address that is associated
with the specific port is permitted.
•
Non IPv4 traffic —
All non-IPv4 traffic is permitted.
See
Interactions with Other Features
for more information about enabling IP
Source Guard on interfaces.