UMN:CLI User Manual
SURPASS hiD 6615 S223/S323 R1.5
262 A50010-Y3-C150-2-7619
To enable IP source guard, DHCP snooping needs to be enabled.
To enable IP source guard with a source IP address filtering on a port, use the following
command.
Command Mode
Description
ip dhcp verify source
PORTS
Enables IP source guard with a source IP address
filtering on a port.
no ip dhcp verify source
PORTS
Global
Disables IP source guard.
To enable IP source guard with a source IP address and MAC address filtering on a port,
use the following command.
Command Mode
Description
ip dhcp verify source port-
security
PORTS
Enables IP source guard with a source IP address and
MAC address filtering on a port.
no ip dhcp verify source port-
security
PORTS
Global
Disables IP source guard.
You cannot configure IP source guard with the
ip dhcp verify source
and
ip dhcp verify
source port-security
commands together.
8.8.8.2
Static IP Source Binding
The IP source binding table has bindings that are learned by DHCP snooping or manually
specified with the
ip dhcp verify source binding
command. The switch uses the IP
source binding table only when IP source guard is enabled.
To specify a static IP source binding entry, use the following command.
Command Mode
Description
ip dhcp verify source binding
<1-4094>
PORT
A.B.C.D
MAC-
ADDR
Specifies a static IP source binding entry.
1-4094: VLAN ID
PORT: port number
A.B.C.D: IP address
MAC-ADDR: MAC address
no ip dhcp verify source binding
{
A.B.C.D
|
all
}
Global
Deletes a specified static IP source binding.
8.8.8.3
Displaying IP Source Guard Configuration
To display IP source binding table, use the following command.
Command Mode
Description
show ip dhcp verify source
binding
Enable
Global
Shows IP source binding entries.
!
!