346
Configuring IP source guard
Overview
IP source guard (IPSG) prevents spoofing attacks by using an IPSG binding table to match legitimate
packets. It drops all packets that do not match the table.
The IPSG binding table can include the following bindings:
•
IP-interface.
•
MAC-interface.
•
IP-MAC-interface.
•
IP-VLAN-interface.
•
MAC-VLAN-interface.
•
IP-MAC-VLAN-interface.
•
IP-MAC.
IPSG bindings include static bindings that are configured manually and dynamic bindings that are
generated based on information from other modules.
NOTE:
Global IPSG supports only static IP-MAC bindings. For more information about global static IPSG
bindings, see "
As shown in
, IPSG on the interface forwards only the packets that match one of the IPSG
bindings.
Figure 105
Diagram for the IPSG feature
NOTE:
IPSG is a per-interface packet filter. Configuring the feature on one interface does not affect packet
forwarding on another interface.
IP network
Invalid host
Valid host
Configure the IP source guard
feature on the interface
IPSG bindings
1.1.1.1
…
1.1.1.1