Configuring Security
IP Source Guard
Cisco 500 Series Stackable Managed Switch Administration Guide
339
18
•
DHCP packets allowed by DHCP Snooping are permitted.
•
If source IP address filtering is enabled:
-
IPv4 traffic: Only traffic with a source IP address that is associated with
the port is permitted.
-
Non IPv4 traffic: Permitted (Including ARP packets).
Configuring IP Source Guard Work Flow
To configure IP Source Guard:
STEP 1
Enable DHCP Snooping in the
IP Configuration > DHCP >
Properties page or in
the
Security > DHCP Snooping >
Properties
page.
STEP 2
Define the VLANs on which DHCP Snooping is enabled in the
IP Configuration >
DHCP >
Interface Settings page.
STEP 3
Configure interfaces as trusted or untrusted in the
IP Configuration > DHCP >
DHCP Snooping Interface
page.
STEP 4
Enable IP Source Guard in the
Security > IP Source Guard >
Properties page.
STEP 5
Enable IP Source Guard on the untrusted interfaces as required in the
Security >
IP Source Guard >
Interface Settings
page.
STEP 6
View entries to the Binding database in the
Security > IP Source Guard >
Binding
Database page.
Enabling IP Source Guard
To enable IP Source Guard globally:
STEP 1
Click
Security
>
IP Source Guard
>
Properties
. The
Properties
page is
displayed.
STEP 2
Select
Enable
to enable IP Source Guard globally.