251
Figure 76
Network diagram for excluded port application in IP source guard global static binding
GE1/0/1
Device A
Device B
IP: 192.168.0.2/24
MAC: 0001-0203-0406
Gateway: 192.168.0.1/24
Host A
IP: 192.168.1.2/24
MAC: 0001-0203-0407
Gateway: 192.168.1.1/24
Host B
Vlan-int10
192.168.0.1/24
VLAN 10
Vlan-int20
192.168.1.1/24
VLAN 20
Global static binding entires
192.168.0.2
192.168.1.2
IP
0001-0203-0407
0001-0203-0406
MAC
0001-0203-0406
Src MAC
192.168.0.2
Src IP
0001-0202-0202
Src MAC
192.168.0.2
Src IP
NOTE:
After you configure IPv4 or IPv6 global static binding entries on a switch, configure the uplink port of
the switch as an excluded port of global static binding to ensure packet forwarding between VLANs.
Dynamic IP source guard binding
Dynamic IP source guard entries are generated dynamically according to client entries on the DHCP
snooping or DHCP relay agent device. They are suitable for scenarios where many hosts reside on a LAN
and obtain IP addresses through DHCP. Once DHCP allocates an IP address to a client, IP source guard
automatically adds the client entry to allow the client to access the network. A user using an IP address
not obtained through DHCP cannot access the network. Dynamic IPv6 source guard entries can also be
obtained from client entries on the ND snooping device.
Dynamic IPv4 source guard binding generates IPv4 source guard binding entries dynamically based
on DHCP snooping or DHCP relay entries to filter IPv4 packets received on a port.
Dynamic IPv6 source guard binding generates IPv6 source guard binding entries dynamically based
on DHCPv6 snooping or ND snooping entries to filter IPv6 packets received on a port.
NOTE:
For information about DHCP snooping and DHCP relay, see the
Layer 3—IP Services Configuration Guide
.
For information about DHCPv6 snooping, see the
Layer 3—IP Services Configuration Guide
.
For information about ND snooping, see the
Layer 3—IP Services Configuration Guide
.
Configuring IPv4 source guard binding
NOTE:
You cannot configure the IP source guard function on a port in an aggregation group, nor can you add
a port configured with IP source guard to an aggregation group.