NOTE:
For descriptions of the results of the various action settings—drop,
log
, none, and shutdown—see “Verifying That MAC Limiting Is Working
Correctly” on page 2937.
Related
Documentation
Configuring MAC Move Limiting (CLI Procedure) on page 2919
•
•
Configuring MAC Move Limiting (J-Web Procedure) on page 2921
•
Configuring Autorecovery From the Disabled State on Secure or Storm Control Interfaces
(CLI Procedure) on page 2796
•
Example: Configuring Port Security, with DHCP Snooping, DAI, MAC Limiting, and MAC
Move Limiting, on an EX Series Switch on page 2849
•
Monitoring Port Security on page 2933
Verifying That IP Source Guard Is Working Correctly
Purpose
Verify that IP source guard is enabled and is mitigating the effects of any source IP
spoofing attacks on the EX Series switch.
Action
Display the IP source guard database.
user@switch>
show ip-source-guard
IP source guard information:
Interface Tag IP Address MAC Address VLAN
ge-0/0/12.0 0 10.10.10.7 00:30:48:92:A5:9D vlan100
ge-0/0/13.0 0 10.10.10.9 00:30:48:8D:01:3D vlan100
ge—0/0/13.0 100 * * voice
Meaning
The IP source guard database table contains the VLANs enabled for IP source guard, the
untrusted access interfaces on those VLANs, the VLAN 802.1Q tag IDs if there are any,
and the IP addresses and MAC addresses that are bound to one another. If a switch
interface is associated with multiple VLANs and some of those VLANs are enabled for
IP source guard and others are not, the VLANs that are not enabled for IP source guard
have a star (*) in the
IP Address
and
MAC Address
fields. See the entry for the
voice
VLAN in the preceding sample output.
Related
Documentation
Configuring IP Source Guard (CLI Procedure) on page 2923
•
Verifying That Proxy ARP Is Working Correctly
Purpose
Verify that the switch is sending proxy ARP messages.
Action
List the system statistics for ARP:
Copyright © 2010, Juniper Networks, Inc.
2942
Complete Software Guide for Junos
®
OS for EX Series Ethernet Switches, Release 10.3
Summary of Contents for JUNOS OS 10.3 - SOFTWARE
Page 325: ...CHAPTER 17 Operational Mode Commands for System Setup 229 Copyright 2010 Juniper Networks Inc ...
Page 1323: ...CHAPTER 56 Operational Mode Commands for Interfaces 1227 Copyright 2010 Juniper Networks Inc ...
Page 2841: ...CHAPTER 86 Operational Commands for 802 1X 2745 Copyright 2010 Juniper Networks Inc ...
Page 3367: ...CHAPTER 113 Operational Mode Commands for CoS 3271 Copyright 2010 Juniper Networks Inc ...
Page 3435: ...CHAPTER 120 Operational Mode Commands for PoE 3339 Copyright 2010 Juniper Networks Inc ...
Page 3529: ...CHAPTER 126 Operational Mode Commands for MPLS 3433 Copyright 2010 Juniper Networks Inc ...