Configuring Device Security
Defining DHCP Snooping
ESW 500 Series Switches Administration Guide
186
5
Defining IP Source Guard Interface Settings
In the
IP Source Guard Interface Settings Page
, IP Source Guard can be enabled
on DHCP Snooping untrusted interfaces, permitting the transmission of DHCP
packets allowed by DHCP Snooping. If source IP address filtering is enabled,
packet transmission is permitted as follows:
•
IPv4 traffic — Only IPv4 traffic with a source IP address that is associated with
the specific port is permitted.
•
Non IPv4 traffic — All non-IPv4 traffic is permitted.
NOTE:
IP Source Guard must be enabled globally in the
IP Source Guard
Properties Page
before it can be enabled on the device interfaces.
If a port is trusted, filtering of static IP addresses can be configured, although IP
Source Guard is not active in that condition.
If a port’s status changes from untrusted to trusted, the static IP address filtering
entries remain but become inactive.