C
ONFIGURING
THE
S
WITCH
3-238
When enabled, traffic is filtered based upon dynamic entries learned via
DHCP snooping or static addresses configured in the source guard
binding table. An inbound packet’s IP address (sip option) or both its IP
address and corresponding MAC address (sip-mac option) are checked
against the binding table. If no matching entry is found, the packet is
dropped.
Command Attributes
•
Filter Type
– Configures the switch to filter inbound traffic based
source IP address, or source IP address and corresponding MAC
address. (Default: None)
-
None
– Disables IP source guard filtering on the port.
-
SIP
– Enables traffic filtering based on IP addresses stored in the
binding table.
-
SIP-MAC
– Enables traffic filtering based on IP addresses and
corresponding MAC addresses stored in the binding table.
Web
– Click IP Source Guard, Port Configuration.
Figure 3-111. IP Source Guard Port Configuration
Summary of Contents for 6128L2
Page 2: ......
Page 21: ...CONTENTS xvii Glossary Index ...
Page 22: ...CONTENTS xviii ...
Page 26: ...TABLES xxii ...
Page 40: ...INTRODUCTION 1 10 ...
Page 54: ...INITIAL CONFIGURATION 2 14 ...
Page 193: ...PORT CONFIGURATION 3 139 Figure 3 61 Displaying Etherlike and RMON Statistics ...
Page 257: ...QUALITY OF SERVICE 3 203 Figure 3 90 Configuring Policy Maps ...
Page 313: ...COMMAND GROUPS 4 13 PE Privileged Exec VC VLAN Database Configuration ...
Page 592: ...TROUBLESHOOTING B 4 ...
Page 605: ......