C
HAPTER
25
| General Security Measures
IP Source Guard
– 669 –
IP S
OURCE
G
UARD
IP Source Guard is a security feature that filters IP traffic on network
interfaces based on manually configured entries in the IP Source Guard
table, or dynamic entries in the DHCP Snooping table when enabled (see
"DHCP Snooping" on page 660
). IP source guard can be used to prevent
traffic attacks caused when a host tries to use the IP address of a neighbor
to access the network. This section describes commands used to configure
IP Source Guard.
ip source-guard
binding
This command adds a static address to the source-guard binding table. Use
the
no
form to remove a static entry.
S
YNTAX
ip source-guard binding
mac-address
vlan
vlan-id ip-address
interface ethernet
unit/port
no
ip source-guard
binding
mac-address
vlan
vlan-id
mac-address
- A valid unicast MAC address.
vlan-id
- ID of a configured VLAN (Range: 1-4093)
ip-address
- A valid unicast IP address, including classful types A, B
or C.
unit
- Unit identifier. (Range: 1)
port
- Port number. (Range: 1-10)
D
EFAULT
S
ETTING
No configured entries
C
OMMAND
M
ODE
Global Configuration
C
OMMAND
U
SAGE
◆
Table entries include a MAC address, IP address, lease time, entry type
(Static-IP-SG-Binding, Dynamic-DHCP-Binding), VLAN identifier, and
port identifier.
Table 79: IP Source Guard Commands
Command
Function
Mode
ip source-guard binding
Adds a static address to the source-guard binding
table
GC
ip source-guard
Configures the switch to filter inbound traffic based
on source IP address, or source IP address and
corresponding MAC address
IC
show ip source-guard
Shows whether source guard is enabled or disabled
on each interface
PE
show ip source-guard
binding
Shows the source guard binding table
PE
Содержание ES3510MA
Страница 1: ...Management Guide www edge core com 8 Port Layer 2 Fast Ethernet Switch...
Страница 4: ...ABOUT THIS GUIDE 4...
Страница 30: ...CONTENTS 30...
Страница 40: ...FIGURES 40...
Страница 46: ...TABLES 46...
Страница 48: ...SECTION I Getting Started 48...
Страница 72: ...SECTION II Web Configuration 72...
Страница 88: ...CHAPTER 3 Using the Web Interface Navigating the Web Browser Interface 88...
Страница 115: ...CHAPTER 4 Basic Management Tasks Resetting the System 115 Figure 23 Restarting the Switch Regularly...
Страница 116: ...CHAPTER 4 Basic Management Tasks Resetting the System 116...
Страница 154: ...CHAPTER 5 Interface Configuration VLAN Trunking 154...
Страница 216: ...CHAPTER 8 Spanning Tree Algorithm Configuring Interface Settings for MSTP 216...
Страница 350: ...CHAPTER 14 Security Measures DHCP Snooping 350...
Страница 440: ...CHAPTER 17 IP Services Displaying the DNS Cache 440...
Страница 484: ...CHAPTER 19 Using the Command Line Interface CLI Command Groups 484...
Страница 554: ...CHAPTER 21 System Management Commands Switch Clustering 554...
Страница 574: ...CHAPTER 22 SNMP Commands 574...
Страница 582: ...CHAPTER 23 Remote Monitoring Commands 582...
Страница 636: ...CHAPTER 24 Authentication Commands Management IP Filter 636...
Страница 736: ...CHAPTER 29 Port Mirroring Commands RSPAN Mirroring Commands 736...
Страница 816: ...CHAPTER 34 VLAN Commands Configuring Voice VLANs 816...
Страница 830: ...CHAPTER 35 Class of Service Commands Priority Commands Layer 3 and 4 830...
Страница 848: ...CHAPTER 36 Quality of Service Commands 848...
Страница 900: ...CHAPTER 38 LLDP Commands 900...
Страница 910: ...CHAPTER 39 Domain Name Service Commands 910...
Страница 916: ...CHAPTER 40 DHCP Commands DHCP Client 916...
Страница 948: ...CHAPTER 41 IP Interface Commands IPv6 Interface 948...
Страница 950: ...SECTION IV Appendices 950...
Страница 982: ...INDEX 982...
Страница 983: ......
Страница 984: ...ES3510MA E032010 ST R01 149100000046A...