C
HAPTER
24
| General Security Measures
IPv4 Source Guard
– 929 –
◆
Filtering rules are implemented as follows:
■
If DHCPv4 snooping is disabled (see
page 906
), IP source guard will
check the VLAN ID, source IP address, port number, and source
MAC address (for the sip-mac option). If a matching entry is found
in the binding table and the entry type is static IP source guard
binding, the packet will be forwarded.
■
If the DHCP snooping is enabled, IP source guard will check the
VLAN ID, source IP address, port number, and source MAC address
(for the sip-mac option). If a matching entry is found in the binding
table and the entry type is static IP source guard binding, or
dynamic DHCP snooping binding, the packet will be forwarded.
■
If IP source guard if enabled on an interface for which IP source
bindings (dynamically learned via DHCP snooping or manually
configured) are not yet configured, the switch will drop all IP traffic
on that port, except for DHCP packets.
■
Only unicast addresses are accepted for static bindings.
E
XAMPLE
This example enables IP source guard on port 5.
Console(config)#interface ethernet 1/5
Console(config-if)#ip source-guard sip
Console(config-if)#
R
ELATED
C
OMMANDS
ip source-guard binding (926)
ip dhcp snooping (906)
ip dhcp snooping vlan (911)
ip source-guard
max-binding
This command sets the maximum number of entries that can be bound to
an interface. Use the
no
form to restore the default setting.
S
YNTAX
ip source-guard
[
mode
{
acl
|
mac
}]
max-binding
number
no
ip source-guard
[
mode
{
acl
|
mac
}]
max-binding
mode
- Specifies the learning mode.
acl
- Searches for addresses in the ACL table.
mac
- Searches for addresses in the MAC address table.
number
- The maximum number of IP addresses that can be
mapped to an interface in the binding table. (Range: 1-5 for ACL
mode; 1-1024 for MAC mode)
D
EFAULT
S
ETTING
5
Содержание ECS3510-10PD
Страница 1: ...Management Guide www edge core com 10 Port Layer 2 Fast Ethernet Switch...
Страница 2: ......
Страница 4: ......
Страница 48: ...CONTENTS 48...
Страница 68: ...SECTION I Getting Started 68...
Страница 78: ...CHAPTER 1 Introduction System Defaults 78...
Страница 96: ...CHAPTER 2 Initial Switch Configuration Managing System Files 96...
Страница 98: ...SECTION II Web Configuration 98...
Страница 118: ...CHAPTER 3 Using the Web Interface Navigating the Web Browser Interface 118...
Страница 150: ...CHAPTER 4 Basic Management Tasks Resetting the System 150...
Страница 196: ...CHAPTER 5 Interface Configuration VLAN Trunking 196 Figure 66 Configuring VLAN Trunking...
Страница 238: ...CHAPTER 7 Address Table Settings Configuring MAC Address Mirroring 238...
Страница 264: ...CHAPTER 8 Spanning Tree Algorithm Configuring Interface Settings for MSTP 264...
Страница 274: ...CHAPTER 9 Congestion Control Automatic Traffic Control 274...
Страница 288: ...CHAPTER 10 Class of Service Layer 3 4 Priority Settings 288...
Страница 304: ...CHAPTER 11 Quality of Service Attaching a Policy Map to a Port 304...
Страница 423: ...CHAPTER 13 Security Measures DHCP Snooping 423 Figure 229 Displaying the Binding Table for DHCP Snooping...
Страница 424: ...CHAPTER 13 Security Measures DHCP Snooping 424...
Страница 568: ...CHAPTER 14 Basic Administration Protocols OAM Configuration 568...
Страница 596: ...CHAPTER 15 IP Configuration Setting the Switch s IP Address IP Version 6 596...
Страница 614: ...CHAPTER 1 IP Services Configuring the PPPoE Intermediate Agent 614...
Страница 784: ...CHAPTER 20 System Management Commands Powered Device 784...
Страница 814: ...CHAPTER 22 Remote Monitoring Commands 814...
Страница 1008: ...CHAPTER 26 Interface Commands Power Savings 1008...
Страница 1022: ...CHAPTER 27 Link Aggregation Commands Trunk Status Display Commands 1022...
Страница 1052: ...CHAPTER 29 Congestion Control Commands Automatic Traffic Control Commands 1052...
Страница 1064: ...CHAPTER 31 UniDirectional Link Detection Commands 1064...
Страница 1070: ...CHAPTER 32 Address Table Commands 1070...
Страница 1130: ...CHAPTER 34 ERPS Commands 1130...
Страница 1172: ...CHAPTER 35 VLAN Commands Configuring Voice VLANs 1172...
Страница 1186: ...CHAPTER 36 Class of Service Commands Priority Commands Layer 3 and 4 1186...
Страница 1302: ...CHAPTER 38 Multicast Filtering Commands MVR for IPv6 1302...
Страница 1368: ...CHAPTER 40 CFM Commands Delay Measure Operations 1368...
Страница 1390: ...CHAPTER 42 Domain Name Service Commands 1390...
Страница 1448: ...CHAPTER 44 IP Interface Commands ND Snooping 1448...
Страница 1450: ...SECTION IV Appendices 1450...
Страница 1455: ...APPENDIX A Software Specifications Management Information Bases 1455 UDP MIB RFC 2013...
Страница 1456: ...APPENDIX A Software Specifications Management Information Bases 1456...
Страница 1464: ...APPENDIX D Compliances and Safety Statements CE Mark Declaration of Conformance for EMI and Safety EEC 1464...
Страница 1482: ...COMMAND LIST 1482...
Страница 1493: ......
Страница 1494: ...ECS3510 10PD E032014 ST R03 149100000179A...