60-28
Catalyst 4500 Series Switch, Cisco IOS Software Configuration Guide - Cisco IOS XE 3.9.xE and IOS 15.2(5)Ex
Chapter 60 Configuring DHCP Snooping, IP Source Guard, and IPSG for Static Hosts
Configuring IP Source Guard for Static Hosts
The following example displays all inactive IP-to-MAC binding entries for all interfaces. The host was
first learned on GigabitEthernet 3/1 then moved to GigabitEthernet 4/1. The IP-to-MAC binding entries
learned on GigabitEthernet 3/1 are marked as inactive.
Switch#
show ip device tracking all inactive
IP Device Tracking = Enabled
IP Device Tracking Probe Count = 3
IP Device Tracking Probe Interval = 30
---------------------------------------------------------------------
IP Address MAC Address Vlan Interface STATE
---------------------------------------------------------------------
200.1.1.8 0001.0600.0000 8 GigabitEthernet3/1 INACTIVE
200.1.1.9 0001.0600.0000 8 GigabitEthernet3/1 INACTIVE
200.1.1.10 0001.0600.0000 8 GigabitEthernet3/1 INACTIVE
200.1.1.1 0001.0600.0000 8 GigabitEthernet3/1 INACTIVE
200.1.1.2 0001.0600.0000 8 GigabitEthernet3/1 INACTIVE
200.1.1.3 0001.0600.0000 8 GigabitEthernet3/1 INACTIVE
200.1.1.4 0001.0600.0000 8 GigabitEthernet3/1 INACTIVE
200.1.1.5 0001.0600.0000 8 GigabitEthernet3/1 INACTIVE
200.1.1.6 0001.0600.0000 8 GigabitEthernet3/1 INACTIVE
200.1.1.7 0001.0600.0000 8 GigabitEthernet3/1 INACTIVE
The following example display the count of all IP device tracking host entries for all interfaces:
Switch#
show ip device tracking all count
Total IP Device Tracking Host entries: 5
---------------------------------------------------------------------
Interface Maximum Limit Number of Entries
---------------------------------------------------------------------
Fa4/3 5
Configuring IPSG for Static Hosts on a PVLAN Host Port
You can configure IPSG for static hosts on a PVLAN host port.
To enable IPSG for static hosts with IP filters on a PVLAN host port, perform this task:
Command
Purpose
Step 1
Switch(config)#
vlan
n1
Enters configuration VLAN mode.
Step 2
Switch(config-vlan)#
private-vlan primary
Establishes a primary VLAN on a PVLAN port.
Step 3
Switch(config-vlan)#
exit
Exits VLAN configuration mode.
Step 4
Switch(config)#
vlan
n2
Enters configuration VLAN mode.
Step 5
Switch(config-vlan)#
private-vlan isolated
Establishes an isolated VLAN on a PVLAN port.
Step 6
Switch(config-vlan)#
exit
Exits VLAN configuration mode.
Step 7
Switch(config)#
vlan
n1
Enters configuration VLAN mode.
Step 8
Switch(config-vlan)#
private-vlan association 201
Associates the VLAN on an isolated PVLAN port.
Step 9
Switch(config-vlan)#
exit
Exits VLAN configuration mode.
Step 10
Switch(config)#
interface fastEthernet
a/b
Enters interface configuration mode.
Step 11
Switch(config-if)#
switchport mode private-vlan
host
(Optional) Establishes a port as a PVLAN host.
Step 12
Switch(config-if)#
switchport private-vlan
host-association
a
b
(Optional) Associates this port with the corresponding
PVLAN.
Summary of Contents for Catalyst 4500 Series
Page 2: ......
Page 4: ......
Page 2086: ...Index IN 46 Software Configuration Guide Release IOS XE 3 9 0E and IOS 15 2 5 E ...