408
•
Static IPv6 source guard binding filters IPv6 packets received by the port or checks the validity of
users by cooperating with the ND detection feature.
NOTE:
•
For information about ARP detection, see "
."
•
For information about ND detection, see "
•
The router does not support static IPv6 source guard binding.
Dynamic IP source guard binding
Dynamic IP source guard entries are generated dynamically according to client entries on the DHCP
snooping or DHCP relay agent device. They are suitable for scenarios where many hosts reside in a
LAN and obtain IP addresses through DHCP. Once DHCP allocates an IP address to a client, IP source
guard automatically adds the client entry to allow the client to access the network. A user using an IP
address not obtained through DHCP cannot access the network. Dynamic IPv6 source guard entries can
also be obtained from client entries on the ND snooping device.
•
Dynamic IPv4 source guard binding generates IPv4 source guard binding entries dynamically
based on DHCP snooping or DHCP relay entries to filter IPv4 packets received on a port.
•
Dynamic IPv6 source guard binding generates IPv6 source guard binding entries dynamically
based on DHCPv6 snooping or ND snooping entries to filter IPv6 packets received on a port.
NOTE:
•
For information about DHCP snooping and DHCP relay, see
Layer 3—IP Services Configuration
Guide.
•
For information about DHCPv6 snooping and ND snooping, see
Layer 3—IP Services Configuration
Guide.
•
The router does not support dynamic IPv6 source guard binding.
Configuring IPv4 source guard binding
Configuring a static IPv4 source guard binding entry
To do…
Command…
Remarks
1.
Enter system view.
system-view
—
2.
Enter interface view.
interface
interface-type
interface-
number
—
3.
Configure a static IPv4
source guard binding
entry.
user-bind
{
ip-address
ip-address
|
ip-address
ip-address
mac-address
mac-address
|
mac-address
mac-
address
} [
vlan
vlan-id
]
Required.
No static IPv4 source guard
binding entry exists by default.
A static source guard binding
entry can be configured only on
Layer 2 Ethernet ports.