Operation Manual – IP Source Guard
H3C S5500-EI Series Ethernet Switches
Chapter 1 IP Source Guard Configuration
1-1
Chapter 1 IP Source Guard Configuration
When configuring IP Source Guard, go to these sections for information you are
interested in:
z
IP Source Guard Overview
z
Configuring a Static Binding Entry
z
Configuring Dynamic Binding Function
z
Displaying IP Source Guard
z
IP Source Guard Configuration Examples
z
Troubleshooting
1.1 IP Source Guard Overview
By filtering packets on a per-port basis, IP source guard prevents packets with illegal IP
addresses and MAC addresses from traveling through, improving the network security.
After receiving a packet, the port looks up the key attributes (including IP address, MAC
address and VLAN tag) of the packet in the binding entries of the IP source guard. If
there is a matching entry, the port will forward the packet. Otherwise, the port will
abandon the packet.
IP source guard filters packets based on the following types of binding entries:
z
IP-port binding entry
z
MAC-port binding entry
z
IP-MAC-port binding entry
You can manually set static binding entries, or use DHCP Snooping to provide dynamic
binding entries. Binding is on a per-port basis. After a binding entry is configured on a
port, it is effective only to the port, instead of other ports.
Caution:
IP source guard and aggregation group configuration are mutually exclusive.
1.2 Configuring a Static Binding Entry
Follow these steps to configure a static binding entry: