812
Snooping and Inspecting Traffic
Configuring IP Source Guard
Beginning in Privileged EXEC mode, use the following commands to
configure IPSG settings on the switch.
Command
Purpose
configure
Enter global configuration mode.
interface
interface
Enter interface configuration mode for the specified port
or LAG. The
interface
variable includes the interface type
and number, for example
gigabitethernet 1/0/3
. For a
LAG, the interface type is
port-channel
.
You can also specify a range of ports with the
interface
range
command, for example,
interface range
gigabitethernet 1/0/8-12
configures interfaces 8, 9, 10, 11,
and 12.
ip verify source [port-
security]
Enable IPSG on the port or LAG to prevent packet
forwarding if the source IP address in the packet is not in
the DHCP snooping binding database. Use the option
port-security keyword
to also prevent packet forwarding if
the sender MAC address is not in forwarding database
table or the DHCP snooping binding database. \
NOTE:
To enforce filtering based on the source MAC
address, port security must also be enabled on the interface
by using the port security command in Interface
Configuration mode.
exit
Exit to Global Config mode.
ip verify binding
mac_addr
vlan
vlan_id
ipaddr
interface
interface
Configure a static binding for IPSG.
exit
Exit to Privileged EXEC mode.
show ip verify interface
interface
View IPSG parameters for a specific port or LAG. The
interface
parameter includes the interface type
(
gigabitethernet
,
tengigabitethernet
, or
port-channel
)
and number.
show ip verify source
[interface
interface
]
View IPSG bindings configured on the switch or on a
specific port or LAG.
show ip source binding
View IPSG bindings.
Summary of Contents for PowerConnect 7024
Page 134: ...134 Setting Basic Network Information ...
Page 290: ...290 Managing General System Settings Figure 11 14 SNTP Servers Table ...
Page 348: ...348 Configuring SNMP ...
Page 430: ...430 Monitoring Switch Traffic ...
Page 444: ...444 Configuring iSCSI Optimization ...
Page 538: ...538 Configuring 802 1X and Port Based Security ...
Page 594: ...594 Configuring VLANs Figure 21 16 GVRP Port Parameters Table ...
Page 600: ...600 Configuring VLANs Figure 21 23 Double VLAN Port Parameter Table ...
Page 658: ...658 Configuring the Spanning Tree Protocol ...
Page 693: ...Configuring Port Based Traffic Control 693 Figure 24 3 Storm Control 5 Click Apply ...
Page 780: ...780 Configuring Connectivity Fault Management ...
Page 804: ...804 Snooping and Inspecting Traffic Figure 27 17 DAI Interface Configuration Summary ...
Page 818: ...818 Snooping and Inspecting Traffic ...
Page 836: ...836 Configuring Link Aggregation ...
Page 882: ...882 Configuring DHCP Server Settings ...
Page 916: ...916 Configuring L2 and L3 Relay Features Figure 33 3 DHCP Relay Interface Summary ...
Page 924: ...924 Configuring L2 and L3 Relay Features Figure 33 12 IP Helper Statistics ...
Page 930: ...930 Configuring L2 and L3 Relay Features ...
Page 1004: ...1004 Configuring OSPF and OSPFv3 ...
Page 1044: ...1044 Configuring VRRP ...
Page 1057: ...Configuring IPv6 Routing 1057 Figure 37 9 IPv6 Route Preferences ...
Page 1064: ...1064 Configuring IPv6 Routing ...
Page 1084: ...1084 Configuring DHCPv6 Server and Relay Settings ...
Page 1091: ...Configuring Differentiated Services 1091 Figure 39 5 DiffServ Class Criteria ...
Page 1114: ...1114 Configuring Differentiated Services ...
Page 1130: ...1130 Configuring Class of Service ...
Page 1136: ...1136 Configuring Auto VoIP ...
Page 1216: ...1216 Managing IPv4 and IPv6 Multicast ...