1-3
z
Cooperating with DHCP snooping, IP source guard will automatically obtain the DHCP snooping
entries that are generated during dynamic IP address allocation on a Layer 2 Ethernet port.
z
Cooperating with DHCP Relay, IP source guard will automatically obtain the DHCP Relay entries
that are generated during dynamic IP address allocation across network segments on a VLAN
interface.
These dynamically obtained binding entries contain such information as MAC address, IP address,
VLAN tag, port information and entry type. IP source guard applies these binding entries to the port, so
that the port can filter packets according to the binding entries.
Follow these steps to configure port filtering:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter interface view
interface interface-type
interface-number
—
Configure dynamic binding
function
ip check source
{
ip-address
|
ip-address
mac-address
|
mac-address
}
Required
Not configured by default
z
To implement dynamic binding in IP source guard, make sure that DHCP snooping or DHCP Relay
is configured and works normally. For DHCP configuration information, refer to
DHCP
Configuration
in the
System Volume
.
z
A port takes only the latest dynamic binding entries configured on it.
Displaying and Maintaining IP Source Guard
To do…
Use the command…
Remarks
Display information about static
binding entries
display user-bind
[
interface
interface-type interface-number
|
ip-address ip-address
|
mac-address mac-address
]
Available in any view
Display information about
dynamic binding entries on a
distributed device
display ip check source
[
interface interface-type
interface-number | ip-address
ip-address | mac-address
mac-address
] [
slot
slot-number
]
Available in any view
Display information about
dynamic binding entries on a
distributed IRF device
display ip check source
[
interface interface-type
interface-number | ip-address
ip-address | mac-address
mac-address
] [
chassis
chassis-number
slot
slot-number
]
Available in any view
Содержание S7902E
Страница 82: ...1 4 DeviceA interface tunnel 1 DeviceA Tunnel1 service loopback group 1 ...
Страница 200: ...1 11 DeviceB display vlan dynamic No dynamic vlans exist ...
Страница 494: ...ii Displaying and Maintaining Tunneling Configuration 1 45 Troubleshooting Tunneling Configuration 1 45 ...
Страница 598: ...ii ...
Страница 1757: ...4 9 ...
Страница 1770: ...6 4 ...
Страница 2017: ...2 11 Figure 2 3 SFTP client interface ...
Страница 2062: ...i Table of Contents 1 URPF Configuration 1 1 URPF Overview 1 1 What is URPF 1 1 How URPF Works 1 1 Configuring URPF 1 2 ...
Страница 2238: ...1 16 DeviceA cfd linktrace service instance 1 mep 1001 target mep 4002 ...
Страница 2442: ...2 4 Set the interval for sending Syslog or trap messages to 20 seconds Device mac address information interval 20 ...