How to Configure IP Source Guard
Enabling IP Source Guard
SUMMARY STEPS
1.
configure terminal
2.
interface interface-id
3.
ip verify source
[
mac-check
]
4.
exit
5.
ip source binding mac-address vlan vlan-id ip-address interface interface-id
6.
end
DETAILED STEPS
Purpose
Command or Action
Enters the global configuration mode.
configure terminal
Example:
Switch#
configure terminal
Step 1
Specifies the interface to be configured, and enters
interface configuration mode.
interface interface-id
Example:
Switch(config)#
interface gigabitethernet 1/0/1
Step 2
Enables IP source guard with source IP address filtering.
ip verify source
[
mac-check
]
Step 3
Example:
Switch(config-if)#
ip verify source
(Optional)
mac-check
—
Enables IP Source Guard with
source IP address and MAC address filtering.
Returns to global configuration mode.
exit
Example:
Switch(config-if)#
exit
Step 4
Adds a static IP source binding.
ip source binding mac-address vlan vlan-id ip-address
interface interface-id
Step 5
Enter this command for each static binding.
Example:
Switch(config)#
ip source binding 0100.0230.0002
vlan 11 10.0.0.4 interface gigabitethernet1/0/1
Catalyst 2960-XR Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX1
188
OL-29434-01
Configuring IP Source Guard
How to Configure IP Source Guard