Mypower
S4100
Troubleshooting
Maipu Confidential & Proprietary Information
Page
67
of
124
Possible Reasons
Judging Methods and Solutions
Only ip source binding is
configured, but IP SOURCE
GUARD is not enabled.
Check the configuration. Besides binding entries, the IP
SOURCE GUARD check based on IP or IP
+
MAC needs to be
enabled.
IP SOURCE GUARD is
enabled, but the addresses
are not distributed via
DHCPSNOOPING.
The port enables the IP SOURCE GUARD check based on MAC
or IP
+
MAC. Distribute IP addresses via DHCP, but
DHCPSNOOPING is not enabled. You need to enable
DHCSNOOPING to get the IP addresses and MAC addresses
distributed by DHCP to realize the binding.
The number of the entries
exceeds the maximum and
some entries become invalid.
Use the show ip binding table command to view whether
there are invalid binding entries. Delete the invalid binding
entries to release the resources and satisfy the application.
The enabled is the IP-based
IP SOURCE GUARD binding,
but the expected is filtering
IP
+
MAC.
View whether the configured is ip verify source ip-mac, but
not ip verify source.
Fault 2: The maximum number of the configurable IP SOURCE GUARD
entries is not fixed.
Possible Reasons
Judging Methods and Solutions
Enabling IP SOURCE GUARD
on each port occupies two ip
source binding.
As long as enabling IP SOURCE GUARD, each port occupies
two ip source binding. One is to permit DHCP packets to pass
and the other is to deny all un-permitted packets. Therefore, if
the number of the ports on which IP SOURCE GUARD is
enabled is different, the maximum number of valid entries
configured by the user is different.
There remaining idle binding
resources cannot be used by
the distributing rule.
IP SOURCE GUARD of each port occupies two ip source
binding. One is to permit DHCP packets to pass and the other
is to deny the un-permitted packets. Therefore, the entries
configured by the user must be distributed between the two
resources. When the idle resources are out of the two
resources, the idle resources cannot be used.
Fault 3: The original valid binding entries become invalid after restarting
the system.
Possible Reasons
Judging Methods and Solutions
The resources are distributed
according to the
configuration order during
the configuration, while the
resources are distributed
according to the port order
when restarting the loading
configuration scripts.
The orders of distributing resources in the two modes are
different. If the resources are first distributed to the port with
large serial number during the configuration, while lots of
binding entries whose number exceeds the maximum are
configured on the port with small serial number at last.
However, when restarting the loading configuration script, the
resources are first distributed to the port with small serial
number, which makes the original valid binding entries of the
port with large serial number become invalid and the original