22-21
Catalyst 3750-E and 3560-E Switch Software Configuration Guide
OL-9775-08
Chapter 22 Configuring DHCP Features and IP Source Guard
Configuring IP Source Guard
This example shows how to stop IPSG with static hosts on an interface.
Switch(config-if)#
no ip verify source
Switch(config-if)#
no ip device tracking max
This example shows how to enable IPSG with static hosts on a port.
Switch(config)#
ip device tracking
Switch(config)#
ip device tracking max 10
Switch(config-if)#
ip verify source tracking port-security
This example shows how to enable IPSG for static hosts with IP filters on a Layer 2 access port and to
verify the valid IP bindings on the interface Gi1/0/3:
Switch#
configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
Switch(config)#
ip device tracking
Step 6
ip verify source tracking port-security
Enable IPSG for static hosts with MAC address filtering.
Note
When you enable both IP source guard and port
security by using the
ip verify source
port-security
interface configuration command:
•
The DHCP server must support option 82, or
the client is not assigned an IP address.
•
The MAC address in the DHCP packet is not
learned as a secure address. The MAC address
of the DHCP client is learned as a secure
address only when the switch receives
non-DHCP data traffic.
Step 7
ip device tracking maximum
number
Establish a maximum limit for the number of static IPs
that the IP device tracking table allows on the port. The
range is 1to 10. The maximum number is 10.
Note
You must configure the
ip device tracking
maximum
limit-number
interface configuration
command.
Step 8
switchport port-security
(Optional) Activate port security for this port.
Step 9
switchport port-security maximum
value
(Optional) Establish a maximum of MAC addresses for
this port.
Step 10
end
Return to privileged EXEC mode.
Step 11
show ip verify source interface
interface-id
Verify the configuration and display IPSG permit ACLs
for static hosts.
Step 12
show ip device track all
[active | inactive] count
Verify the configuration by displaying the IP-to-MAC
binding for a given host on the switch interface.
•
all active
—display only the active IP or MAC
binding entries
•
all inactive
—display only the inactive IP or MAC
binding entries
•
all
—display the active and inactive IP or MAC
binding entries
Command
Purpose
Содержание Catalyst 3750-E Series
Страница 48: ...Contents xlviii Catalyst 3750 E and 3560 E Switch Software Configuration Guide OL 9775 08 ...
Страница 52: ...lii Catalyst 3750 E and 3560 E Switch Software Configuration Guide OL 9775 08 Preface ...
Страница 1414: ...Index IN 58 Catalyst 3750 E and 3560 E Switch Software Configuration Guide OL 9775 08 ...