Configuration Guide
IP Source Guard Configuration
privately in the DHCP network, enable IP Source Guard on the device connecting the
DHCP server to the DHCP clients. DHCP Snooping-based IP Source Guard
ensures that DHCP clients access network resources properly and block the users
who assign addresses privately to access.
IP Source Guard
IP Source Guard maintains a hardware-based IP packet filtering database to filter
packets, guaranteeing that only the users matching the database can access
network resources.
The hardware-based IP packet filtering database is the key for IP Source Guard to
enable efficient security control in DHCP applications. This database is on the basis
of DHCP Snooping database. After IP Source Guard is enabled, the DHCP Snooping
database is synchronized with the hardware-based IP packet filtering database. In
this way, IP Source Guard can strictly filter IP packets from clients on the device with
DHCP Snooping enabled.
By default, once IP Source Guard is enabled on a port, all the IP packets traveling
through the port (except for DHCP packets) will be checked on the port. Only the
users attaining IP addresses through DHCP and the configured static binding users
can access the network.
IP Source Guard supports source MAC- and source IP-based filtering or source
IP-based filtering. In the former case, IP Source Guard will check the source MAC
and source IP addresses of all packets and only allow those packets matching the
hardware-based IP packet filtering database to pass through. In the latter case, IP
Source Guard checks the source IP addresses of IP packets.
Other Precautions
IP Source Guard is based on DHCP Snooping, namely port-based IP Source Guard
takes effect only on the untrusted port under the control of DHCP Snooping, not on
the trusted port or the interfaces in the VLAN not controlled by DHCP Snooping.
Configuration
Configuring IP Source Guard on the Interface
By default, IP Source Guard is disabled on the interface and all the users connecting
to the interface can use the network. After enabling IP Source Guard on the interface,
it will filter the IP packets of the users connecting to the interface according to the
hardware-based IP packet filtering database.
Command
Description
Ruijie(config)#
interface
interface-id
Enter the interface configuration mode.
Summary of Contents for RG-S2900G-E Series
Page 1: ...RG S2900G E Series Switch RGOS Configuration Guide Release 10 4 2b12 p1 ...
Page 91: ...Configuration Guide Configuring PoE Configuration ...
Page 133: ...Configuration Guide EEE Configuration ...
Page 319: ...Configuration Guide QinQ Configuration ...
Page 408: ......
Page 409: ...IP Routing Configuration 1 Static Route Configuration ...
Page 412: ......
Page 413: ...Multicast Configuration 1 IGMP Snooping Configuration 2 MLD Snooping Configuration ...
Page 757: ......
Page 758: ...ACL QoS Configuration 1 Access Control List Configuration 2 QoS Configuration ...
Page 801: ...Reliability Configuration 1 RLDP Configuration 2 TPP Configuration 3 SEM Configuration ...
Page 901: ...Configuration Guide ERSPAN Configuration ...
Page 902: ...Web based Configuration 1 Web based Configuration ...