MES53xx, MES33xx, MES23xx Ethernet Switch Series
163
no ip source-guard
Disable client IP address protection function for the entire
switch.
ip source-guard binding
mac_address
vlan_idip_address
{gigabitethernet
gi_port
|
tengigabitethernet
te_port
|
fortygigabitethernet
fo_port
|
port-channel
group
}
gi_port: (1..8/0/1..48);
te_port: (1..8/0/1..24);
fo_port: (1..8/0/1..4);
group: (1..16);
vlan_id: (1..4094);
Create an entry with a mapping between the client's IP and
MAC address and VLAN group for the specified interface.
no ip source-guard binding
mac_address vlan_id
Remove a static entry from the mapping table.
ip source-guard tcam
retriesfreq {
seconds
| never}
seconds: (10..600)/60
seconds
Specify the device access rate to internal resources when
saving inactive secured IP addresses into the memory.
-
never
- deny storing inactive secured IP addresses into the
memory.
no ip source-guard tcam
retries-freq
Set the default value.
Ethernet or port group interface (interface range) configuration mode commands
Command line prompt in the Ethernet or port group interface configuration mode is as follows:
console(config-if)#
Table 5.182. Ethernet interface and interface group configuration mode commands
Command
Value/Default value
Action
ip source-guard
This feature is disabled by
default.
Enable client IP address protection feature on the interface.
no ip source-guard
Disable client IP address protection feature on the interface.
Privileged EXEC mode commands
Command line prompt in the Privileged EXEC mode is as follows:
console#
Table 5.183. Privileged EXEC mode commands
Command
Value/Default value
Action
ip source-guard tcam locate
-
Manually start access to internal resources to store inactive
secured IP addresses into the memory. This command is
available to privileged users only.
EXEC mode commands
Command line prompt in the EXEC mode is as follows:
console#
Table 5.184. EXEC mode commands
Command
Value/Default value
Action
show ip source-guard configuration
[gigabitethernet
gi_port
|
tengigabitethernet
te_port
|
fortygigabitethernet
fo_port
|
portchannel
group
]
gi_port: (1..8/0/1..48);
te_port: (1..8/0/1..24);
fo_port: (1..8/0/1..4);
group: (1..16)
This command shows IP address protection configuration
for the selected (or all) device interfaces.
show ip source-guard status
[macaddress
mac_address
]
[ipaddress
ip_address
]
[vlan
vlan_id
]
[gigabitethernet
gi_port
|
tengigabitethernet
te_port
|
fortygigabitethernet
fo_port
|
gi_port: (1..8/0/1..48);
te_port: (1..8/0/1..24);
fo_port: (1..8/0/1..4);
group: (1..16);
vlan_id: (1..4094);
This command shows the status of IP address protection
for the specified interface, IP address, MAC address, and
VLAN group.