Chapter 9
| General Security Measures
IPv4 Source Guard
– 289 –
show ip dhcp
snooping binding
This command shows the DHCP snooping binding table entries.
Command Mode
Privileged Exec
Example
Console#show ip dhcp snooping binding
MAC Address IP Address Lease(sec) Type VLAN Interface
----------------- --------------- ---------- -------------------- ---- ------
11-22-33-44-55-66 192.168.0.99 0 Dynamic-DHCPSNP 1 Eth 1/5
Console#
IPv4 Source Guard
IPv4 Source Guard is a security feature that filters IPv4 traffic on network interfaces
based on manually configured entries in the IPv4 Source Guard table, or dynamic
entries in the DHCPv4 Snooping table when enabled (see
). IPv4 source guard can be used to prevent traffic attacks caused when a
host tries to use the IPv4 address of a neighbor to access the network. This section
describes commands used to configure IPv4 Source Guard.
Table 57: IPv4 Source Guard Commands
Command
Function
Mode
Adds a static address to the source-guard binding
table
GC
Configures the switch to filter inbound traffic based on
source IP address, or source IP address and
corresponding MAC address
IC
Sets the maximum number of entries that can be
bound to an interface
IC
Sets the source-guard learning mode to search for
addresses in the ACL binding table or the MAC
address binding table
IC
Remove all blocked records
PE
Shows whether source guard is enabled or disabled
on each interface
PE
Shows the source guard binding table
PE