Operation Manual – IP Source Guard
H3C S3610&S5510 Series Ethernet Switches
Chapter 1 IP Source Guard Configuration
1-1
Chapter 1 IP Source Guard Configuration
When configuring IP Source Guard, go to these sections for information you are
interested in:
z
z
Configuring a Static Binding Entry
z
z
z
IP Source Guard Configuration Examples
z
1.1 IP Source Guard Overview
By filtering packets on a per-port basis, IP source guard prevents packets with illegal IP
addresses and MAC addresses from traveling through, improving the network security.
IP source guard filters packets based on two types of binding entries:
z
IP-port binding entry: A port permits packets with source IP addresses among its
IP-port binding entries.
z
MAC-IP-port binding entry: A port permits packets with source MAC address and
source IP address pairs among its MAC-IP-port binding entries.
All other packets are denied.
Caution:
IP source guard and aggregation group configuration are mutually exclusive.
1.2 Configuring a Static Binding Entry
Follow these steps to configure a static binding entry:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter interface view
interface interface-type
interface-number
—