![SMC Networks 7724M/VSW - annexe 1 Manual Download Page 333](http://html1.mh-extra.com/html/smc-networks/7724m-vsw-annexe-1/7724m-vsw-annexe-1_manual_1299754333.webp)
CLI
Management Guide
TigerAccess™ EE
332
SMC7824M/VSW
•
Source IP and MAC Address Filter
IP traffic is filtered based on its source IP address as well as its MAC address; only IP
traffic with source IP and MAC addresses matching the IP source binding entry are
permitted. When IP source guard is enabled in IP and MAC filtering mode, the DHCP
snooping option 82 must be enabled to ensure that the DHCP protocol works properly.
Without option 82 data, the switch cannot locate the client host port to forward the
DHCP server reply. Instead, the DHCP server reply is dropped, and the client cannot
obtain an IP address.
8.6.8.1
Enabling IP Source Guard
After configuring DHCP snooping, configure the IP source guard using the provided com-
mand. When IP source guard is enabled with this option, IP traffic is filtered based on the
source IP address. The switch forwards IP traffic when the source IP address matches an
entry in the DHCP snooping binding database or a binding in the IP source binding table.
To enable IP source guard, DHCP snooping needs to be enabled.
To enable IP source guard with a source IP address filtering on a port, use the following
command.
Command Mode
Description
ip dhcp verify source
PORTS
Enables IP source guard with a source IP address
filtering on a port.
no ip dhcp verify source
PORTS
Global
Disables IP source guard.
To enable IP source guard with a source IP address and MAC address filtering on a port,
use the following command.
Command Mode
Description
ip dhcp verify source port-
security
PORTS
Enables IP source guard with a source IP address and
MAC address filtering on a port.
no ip dhcp verify source port-
security
PORTS
Global
Disables IP source guard.
Note that the IP source guard is only enabled on DHCP snooping untrusted Layer 2 port!
If you try to enable this function on a trusted port, the error message will be shown up.
You cannot configure IP source guard with the
ip dhcp verify source
and
ip dhcp verify
source port-security
commands together.
8.6.8.2
Static IP Source Binding
The IP source binding table has bindings that are learned by DHCP snooping or manually
specified with the
ip dhcp verify source binding
command. The switch uses the IP
source binding table only when IP source guard is enabled.
!
!
!
Summary of Contents for 7724M/VSW - annexe 1
Page 1: ......
Page 385: ...CLI Management Guide TigerAccess EE 384 SMC7824M VSW ...
Page 387: ......