252
Configuring a static IPv4 source guard binding entry
Follow these steps to configure a global static IPv4 source guard entry:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Configure a global static IPv4
source guard binding entry
user-bind
ip-address
ip-address
mac-
address
mac-address
Required
No global static binding
entry exists by default.
Enter Layer 2 Ethernet port view
interface
interface-type
interface-number
—
Specify the uplink port as an
excluded port of the global static
binding entry
user-bind uplink
Optional
By default, a port is not an
excluded port. When you
configure global static
binding entries on a switch,
specify the uplink port of
the switch as an excluded
port of the global static
binding entries.
Follow these steps to configure a port-based static IPv4 source guard binding entry:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter Layer 2 Ethernet interface
view
interface
interface-type
interface-
number
—
Configure a static IPv4 source
guard binding entry for the port
user-bind
{
ip-address
ip-address
|
ip-address
ip-address
mac-
address
mac-address
|
mac-
address
mac-address
} [
vlan
vlan-
id
]
Required
No static IPv4 source guard
binding entry exists on a port by
default.
The switch does not support the
vlan
vlan-id
option.
NOTE:
You cannot configure the same static binding entry on one port for multiple times, but you can configure the
same static entry on different ports.
In an IPv4 source guard binding entry, the MAC address cannot be all 0s, all Fs (a broadcast address), or a
multicast address, and the IPv4 address can only be a Class A, Class B, or Class C address and can be neither
127.x.x.x nor 0.0.0.0.
Configuring the dynamic IPv4 source guard binding function
After the dynamic IPv4 source guard binding function is enabled on a port, IP source guard will generate
binding entries dynamically through cooperation with DHCP protocols:
On a Layer 2 Ethernet port, IP source guard cooperates with DHCP snooping, dynamically obtains
the DHCP snooping entries generated during dynamic IP address allocation, and generates IP
source guard entries accordingly.