1-4
IP Source Guard Configuration Examples
Static Binding Entry Configuration Example
Network requirements
As shown in
Figure 1-1
, Host A and Host B are connected to ports GigabitEthernet 2/0/2 and
GigabitEthernet 2/0/1 of Switch B respectively, Host C is connected to port GigabitEthernet 2/0/2 of
Switch A, and Switch B is connected to port GigabitEthernet 2/0/1 of Switch A.
Configure static binding entries on Switch A and Switch B to meet the following requirements:
z
On port GigabitEthernet 2/0/2 of Switch A, only IP packets from Host C can pass.
z
On port GigabitEthernet 2/0/1 of Switch A, only IP packets from Host A can pass.
z
On port GigabitEthernet 2/0/2 of Switch B, only IP packets from Host A can pass.
z
On port GigabitEthernet 2/0/1 of Switch B, only IP packets from Host B can pass.
Figure 1-1
Network diagram for configuring static binding entries
Configuration procedure
1) Configure Switch A
# Configure port GigabitEthernet 2/0/2 of Switch A to allow only IP packets with the source MAC
address of 00-01-02-03-04-05 and the source IP address of 192.168.0.3 to pass.
<SwitchA> system-view
[SwitchA] interface gigabitethernet 2/0/2
[SwitchA-GigabitEthernet2/0/2] user-bind ip-address 192.168.0.3 mac-address 0001-0203-0405
[SwitchA-GigabitEthernet2/0/2] quit
# Configure port GigabitEthernet 2/0/1 of Switch A to allow only IP packets with the source MAC
address of 00-01-02-03-04-06 and the source IP address of 192.168.0.1 to pass.
[SwitchA] interface gigabitethernet 2/0/1
[SwitchA-GigabitEthernet2/0/1] user-bind ip-address 192.168.0.1 mac-address 0001-0203-0406
2) Configure Switch B
# Configure the IP addresses of various interfaces (omitted).
# Configure port GigabitEthernet 2/0/2 of Switch B to allow only IP packets with the source MAC
address of 00-01-02-03-04-06 and the source IP address of 192.168.0.1 to pass.
<SwitchB> system-view
[SwitchB] interface gigabitethernet 2/0/2
[SwitchB-GigabitEthernet2/0/2] user-bind ip-address 192.168.0.1 mac-address 0001-0203-0406
[SwitchB-GigabitEthernet2/0/2] quit
Содержание S7902E
Страница 82: ...1 4 DeviceA interface tunnel 1 DeviceA Tunnel1 service loopback group 1 ...
Страница 200: ...1 11 DeviceB display vlan dynamic No dynamic vlans exist ...
Страница 494: ...ii Displaying and Maintaining Tunneling Configuration 1 45 Troubleshooting Tunneling Configuration 1 45 ...
Страница 598: ...ii ...
Страница 1757: ...4 9 ...
Страница 1770: ...6 4 ...
Страница 2017: ...2 11 Figure 2 3 SFTP client interface ...
Страница 2062: ...i Table of Contents 1 URPF Configuration 1 1 URPF Overview 1 1 What is URPF 1 1 How URPF Works 1 1 Configuring URPF 1 2 ...
Страница 2238: ...1 16 DeviceA cfd linktrace service instance 1 mep 1001 target mep 4002 ...
Страница 2442: ...2 4 Set the interval for sending Syslog or trap messages to 20 seconds Device mac address information interval 20 ...