IP S
OURCE
G
UARD
3-235
When enabled, traffic is filtered based upon dynamic entries learned via
DHCP snooping or static addresses configured in the source guard
binding table. An inbound packet’s IP address (sip option) or both its IP
address and corresponding MAC address (sip-mac option) are checked
against the binding table. If no matching entry is found, the packet is
dropped.
Command Attributes
•
Filter Type
– Configures the switch to filter inbound traffic based
source IP address, or source IP address and corresponding MAC
address. (Default: None)
-
None
– Disables IP source guard filtering on the port.
-
SIP
– Enables traffic filtering based on IP addresses stored in the
binding table.
-
SIP-MAC
– Enables traffic filtering based on IP addresses and
corresponding MAC addresses stored in the binding table.
Web
– Click IP Source Guard, Port Configuration.
Figure 3-111. IP Source Guard Port Configuration
Summary of Contents for 6152L2
Page 2: ......
Page 18: ...TABLES xiv ...
Page 32: ...INTRODUCTION 1 10 ...
Page 46: ...INITIAL CONFIGURATION 2 14 ...
Page 185: ...PORT CONFIGURATION 3 139 Figure 3 61 Displaying Etherlike and RMON Statistics ...
Page 249: ...QUALITY OF SERVICE 3 203 Figure 3 90 Configuring Policy Maps ...
Page 290: ...CONFIGURING THE SWITCH 3 244 ...
Page 303: ...COMMAND GROUPS 4 13 VC VLAN Database Configuration ...
Page 434: ...COMMAND LINE INTERFACE 4 144 ...
Page 568: ...TROUBLESHOOTING B 4 ...
Page 581: ......