
DETAILED STEPS
Purpose
Command or Action
Enters global configuration mode.
configure terminal
Example:
Step 1
switch# configure terminal
switch(config)#
Enters interface configuration mode for the specified
interface.
interface ethernet slot
/
port
Example:
Step 2
switch(config)# interface ethernet 2/3
switch(config-if)#
Enables IP Source Guard on the interface. The
no
form of
this command disables IP Source Guard on the interface.
[
no
]
ip verify source dhcp-snooping-vlan
Example:
Step 3
switch(config-if)# ip verify source dhcp-snooping
vlan
Displays the running configuration for DHCP snooping,
including the IP Source Guard configuration.
(Optional)
show running-config dhcp
Example:
Step 4
switch(config-if)# show running-config dhcp
Copies the running configuration to the startup
configuration.
(Optional)
copy running-config startup-config
Example:
Step 5
switch(config-if)# copy running-config
startup-config
Adding or Removing a Static IP Source Entry
You can add or remove a static IP source entry on the device. By default, there are no static IP source entries.
SUMMARY STEPS
1.
configure terminal
2.
[
no
]
ip source binding ip-address mac-address vlan vlan-id interface interface-type slot
/
port
3.
(Optional)
show ip dhcp snooping binding
[
interface interface-type slot
/
port
]
4.
(Optional)
copy running-config startup-config
DETAILED STEPS
Purpose
Command or Action
Enters global configuration mode.
configure terminal
Example:
Step 1
switch# configure terminal
switch(config)#
Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 9.x
408
Configuring IP Source Guard
Adding or Removing a Static IP Source Entry