UMN:CLI
User Manual
V8102
422
To enable IP source guard with a source IP address and MAC address filtering on a port,
use the following command.
Command
Mode
Description
ip dhcp verify source port-
security
PORTS
Interface
[XE/GE/GPON/CG]
Enables IP source guard with a source IP address
and MAC address filtering on a port.
no ip dhcp verify source port-
security
PORTS
Disables IP source guard.
Note that the IP source guard is only enabled on DHCP snooping untrusted Layer 2 port!
If you try to enable this function on a trusted port, the error message will be shown up.
You cannot configure IP source guard with the
ip dhcp verify source
and
ip dhcp verify
source port-security
commands together.
9.6.8.2
Static IP Source Binding
The IP source binding table has bindings that are learned by DHCP snooping or manually
specified with the
ip dhcp verify source binding
command. The switch uses the IP
source binding table only when IP source guard is enabled.
To specify a static IP source binding entry, use the following command.
Command
Mode
Description
ip dhcp verify source
binding
<1-4094>
A.B.C.D
MAC-ADDR
Interface
[XE/GE/GPON/CG]
Specifies a static IP source binding entry.
1-4094: VLAN ID
A.B.C.D: IP address
MAC-ADDR: MAC address
no ip dhcp verify source
binding
{
A.B.C.D
|
all
}
Deletes a specified static IP source bind-
ing.
9.6.8.3
Displaying IP Source Guard Configuration
To display IP source binding table, use the following command.
Command
Mode
Description
show ip dhcp verify source
binding
Enable
Global
Shows IP source binding entries.
9.6.9
DHCP Client
An interface of the V8102 can be configured as a DHCP client, which can obtain an IP
address from a DHCP server. The configurable DHCP client functionality allows a DHCP
client to use a user-specified client ID, class ID or suggested lease time when requesting
an IP address from a DHCP server. Once configured as a DHCP client, the V8102 cannot
be configured as a DHCP server or relay agent.
!
!