157
Configure port GigabitEthernet 3/0/1 of Switch A to allow only IP packets with the source MAC
address of 00-01-02-03-04-06 and the source IP address of 192.168.0.1 to pass.
[SwitchA] interface gigabitethernet 3/0/1
[SwitchA-GigabitEthernet3/0/1] user-bind ip-address 192.168.0.1 mac-address 0001-
0203-0406
2.
Configure Switch B
Configure the IP addresses of various interfaces (omitted).
Configure port GigabitEthernet 3/0/2 of Switch B to allow only IP packets with the source MAC
address of 00-01-02-03-04-06 and the source IP address of 192.168.0.1 to pass.
<SwitchB> system-view
[SwitchB] interface gigabitethernet 3/0/2
[SwitchB-GigabitEthernet3/0/2] user-bind ip-address 192.168.0.1 mac-address 0001-
0203-0406
[SwitchB-GigabitEthernet3/0/2] quit
Configure port GigabitEthernet 3/0/1 of Switch B to allow only IP packets with the source MAC
address of 00-01-02-03-04-07 and the source IP address of 192.168.0.2 to pass.
[SwitchB] interface gigabitethernet 3/0/1
[SwitchB-GigabitEthernet3/0/1] user-bind ip-address 192.168.0.2 mac-address 0001-
0203-0407
3.
Verify the configuration
On Switch A, static binding entries are configured successfully.
<SwitchA> display user-bind
Total entries found: 2
MAC IP Vlan Port Status
0001-0203-0405 192.168.0.3 N/A GigabitEthernet3/0/2 Static
0001-0203-0406 192.168.0.1 N/A GigabitEthernet3/0/1 Static
On Switch B, static binding entries are configured successfully.
<SwitchB> display user-bind
Total entries found: 2
MAC IP Vlan Port Status
0001-0203-0406 192.168.0.1 N/A GigabitEthernet3/0/2 Static
0001-0203-0407 192.168.0.2 N/A GigabitEthernet3/0/1 Static
Dynamic IP source guard binding function configuration
example I
Network requirements
Switch A connects to Client A and the DHCP server through ports GigabitEthernet 3/0/1 and
GigabitEthernet 3/0/2 respectively. DHCP snooping is enabled on Switch A. See Figure 53.
Detailed requirements are as follows:
•
Client A (with the MAC address of 00-01-02-03-04-06) obtains an IP address through the
DHCP server.