
206
Step Command
Remarks
3.
Configure a static IPv6
binding entry.
ipv6 source binding
ip-address
ipv6-address
[
mac-address
mac-address
] [
vlan
vlan-id
]
By default, no static IPv6 binding entry is
configured on an interface.
IP source guard does not use the VLAN
information (if specified) in static IPv6
source guard binding entries to filter
packets. You do not need to specify the
VLAN information for packet filtering.
The
vlan
vlan-id
option is supported in only
Ethernet interface view.
NOTE:
You cannot configure the same static binding entry on one interface multiple times, but you can configure
the same static binding entry on different interfaces.
Displaying and maintaining IP source guard
Execute
display
commands in any view and
reset
commands in user view.
For IPv4 source guard:
Task Command
Display IPv4 binding
entries.
display ip source binding
[
static
| [
vpn-instance
vpn-instance-name
]
[
dhcp-relay
|
dhcp-server
|
dhcp-snooping
] ]
[
ip-address
ip-address
]
[
mac-address
mac-address
] [
vlan
vlan-id
] [
interface
interface-type
interface-number
] [
slot
slot-number
]
Clear IPv4 biding entries.
reset ip source binding
[
static
[
ip-address
ip-address
] | [
vpn-instance
vpn-instance-name
] [ {
dhcp-relay
|
dhcp-server
|
dhcp-snooping
} [
ip-address
ip-address
] ] ]
For IPv6 source guard:
Task Command
Display static IPv6 binding
entries.
display ipv6 source binding static
[
ip-address
ipv6-address
] [
mac-address
mac-address
] [
vlan
vlan-id
] [
interface
interface-type interface-number
] [
slot
slot-number
]
Clear IPv6 biding entries.
reset ipv6 source binding
[
static
[
ip-address
ipv6-address
] ]
IP source guard configuration examples
Static IPv4 source guard configuration example
Network requirements
As shown in
, Host A is connected to port Ten-GigabitEthernet 1/0/2 of Switch B. Host B is
connected to Ten-GigabitEthernet 1/0/1 of Switch B. Host C is connected to port Ten-GigabitEthernet