C
HAPTER
25
| General Security Measures
IP Source Guard
– 670 –
◆
All static entries are configured with an infinite lease time, which is
indicated with a value of zero by the
show ip source-guard
command
(
page 672
).
◆
When source guard is enabled, traffic is filtered based upon dynamic
entries learned via DHCP snooping, or static addresses configured in
the source guard binding table with this command.
◆
Static bindings are processed as follows:
■
If there is no entry with same VLAN ID and MAC address, a new
entry is added to binding table using the type of static IP source
guard binding.
■
If there is an entry with same VLAN ID and MAC address, and the
type of entry is static IP source guard binding, then the new entry
will replace the old one.
■
If there is an entry with same VLAN ID and MAC address, and the
type of the entry is dynamic DHCP snooping binding, then the new
entry will replace the old one and the entry type will be changed to
static IP source guard binding.
E
XAMPLE
This example configures a static source-guard binding on port 5.
Console(config)#ip source-guard binding 11-22-33-44-55-66 vlan 1 192.168.0.99
interface ethernet 1/5
Console(config-if)#
R
ELATED
C
OMMANDS
ip source-guard (670)
ip dhcp snooping (661)
ip dhcp snooping vlan (665)
ip source-guard
This command configures the switch to filter inbound traffic based source
IP address, or source IP address and corresponding MAC address. Use the
no
form to disable this function.
S
YNTAX
ip source-guard
{
sip
|
sip-mac
}
no
ip source-guard
sip
- Filters traffic based on IP addresses stored in the binding
table.
sip-mac
- Filters traffic based on IP addresses and corresponding
MAC addresses stored in the binding table.
D
EFAULT
S
ETTING
Disabled
Содержание ES3510MA
Страница 1: ...Management Guide www edge core com 8 Port Layer 2 Fast Ethernet Switch...
Страница 4: ...ABOUT THIS GUIDE 4...
Страница 30: ...CONTENTS 30...
Страница 40: ...FIGURES 40...
Страница 46: ...TABLES 46...
Страница 48: ...SECTION I Getting Started 48...
Страница 72: ...SECTION II Web Configuration 72...
Страница 88: ...CHAPTER 3 Using the Web Interface Navigating the Web Browser Interface 88...
Страница 115: ...CHAPTER 4 Basic Management Tasks Resetting the System 115 Figure 23 Restarting the Switch Regularly...
Страница 116: ...CHAPTER 4 Basic Management Tasks Resetting the System 116...
Страница 154: ...CHAPTER 5 Interface Configuration VLAN Trunking 154...
Страница 216: ...CHAPTER 8 Spanning Tree Algorithm Configuring Interface Settings for MSTP 216...
Страница 350: ...CHAPTER 14 Security Measures DHCP Snooping 350...
Страница 440: ...CHAPTER 17 IP Services Displaying the DNS Cache 440...
Страница 484: ...CHAPTER 19 Using the Command Line Interface CLI Command Groups 484...
Страница 554: ...CHAPTER 21 System Management Commands Switch Clustering 554...
Страница 574: ...CHAPTER 22 SNMP Commands 574...
Страница 582: ...CHAPTER 23 Remote Monitoring Commands 582...
Страница 636: ...CHAPTER 24 Authentication Commands Management IP Filter 636...
Страница 736: ...CHAPTER 29 Port Mirroring Commands RSPAN Mirroring Commands 736...
Страница 816: ...CHAPTER 34 VLAN Commands Configuring Voice VLANs 816...
Страница 830: ...CHAPTER 35 Class of Service Commands Priority Commands Layer 3 and 4 830...
Страница 848: ...CHAPTER 36 Quality of Service Commands 848...
Страница 900: ...CHAPTER 38 LLDP Commands 900...
Страница 910: ...CHAPTER 39 Domain Name Service Commands 910...
Страница 916: ...CHAPTER 40 DHCP Commands DHCP Client 916...
Страница 948: ...CHAPTER 41 IP Interface Commands IPv6 Interface 948...
Страница 950: ...SECTION IV Appendices 950...
Страница 982: ...INDEX 982...
Страница 983: ......
Страница 984: ...ES3510MA E032010 ST R01 149100000046A...