253
On a VLAN interface, IP source guard cooperates with DHCP relay, dynamically obtains the DHCP
relay entries generated during dynamic IP address allocation across network segments, and
generates IP source guard entries accordingly.
Dynamic IPv4 source guard entries can contain such information as the MAC address, IP address, VLAN
tag, ingress port information, and entry type (DHCP snooping or DHCP relay), where the MAC address,
IP address, or VLAN tag information may not be included depending on your configuration. IP source
guard applies these entries to the port to filter packets.
Follow these steps to configure the dynamic IPv4 source guard binding function:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter interface view
interface
interface-type interface-
number
—
Configure the dynamic IPv4
source guard binding function
ip check source
{
ip-address
|
ip-
address
mac-address
|
mac-
address
}
Required
Not configured by default
NOTE:
To implement dynamic IPv4 source guard binding in IP source guard, make sure that DHCP snooping or DHCP
relay is configured and works normally. For DHCP configuration information, see the
Layer 3—IP Services
Configuration Guide
.
If you configure dynamic IPv4 source guard binding on a port for multiple times, the last configuration will
overwrite the previous configuration on the port.
Configuring IPv6 source guard binding
NOTE:
You cannot configure the IP source guard function on a port in an aggregation group, nor can you add
a port configured with IP source guard to an aggregation group.
Configuring a static IPv6 source guard binding entry
Follow these steps to configure a global static IPv6 source guard entry:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Configure a global static IPv6
source guard binding entry
user-bind
ipv6 ip-address
ip-address
mac-address
mac-address
Required
No global static binding
entry exists by default.
Enter Layer 2 Ethernet port view
interface
interface-type
interface-number
—