Chapter 8
| General Security Measures
IP Source Guard
– 250 –
IP Source Guard
IP Source Guard is a security feature that filters IP traffic on network interfaces
based on manually configured entries in the IP Source Guard table, or dynamic
entries in the DHCP Snooping table when enabled (see
“DHCP Snooping” on
page 242
). IP source guard can be used to prevent traffic attacks caused when a
host tries to use the IP address of a neighbor to access the network. This section
describes commands used to configure IP Source Guard.
ip source-guard
binding
This command adds a static address to the source-guard binding table. Use the
no
form to remove a static entry.
Syntax
ip source-guard binding
mac-address
vlan
vlan-id ip-address
interface ethernet
unit/port
no
ip source-guard
binding
mac-address
vlan
vlan-id
mac-address
- A valid unicast MAC address.
vlan-id
- ID of a configured VLAN (Range: 1-4093)
ip-address
- A valid unicast IP address, including classful types A, B or C.
unit
- Unit identifier. (Range: 1)
port
- Port number. (Range: 1-28/52)
Default Setting
No configured entries
Command Mode
Global Configuration
Table 51: IP Source Guard Commands
Command
Function
Mode
ip source-guard binding
Adds a static address to the source-guard binding table
GC
ip source-guard
Configures the switch to filter inbound traffic based on
source IP address, or source IP address and
corresponding MAC address
IC
ip source-guard max-binding
Sets the maximum number of entries that can be bound
to an interface
IC
show ip source-guard
Shows whether source guard is enabled or disabled on
each interface
PE
show ip source-guard
binding
Shows the source guard binding table
PE
Содержание EX-3524
Страница 2: ......
Страница 28: ...Figures 28 ...
Страница 34: ...Section I Getting Started 34 ...
Страница 58: ...Chapter 1 Initial Switch Configuration Setting the System Clock 58 ...
Страница 72: ...Chapter 2 Using the Command Line Interface CLI Command Groups 72 ...
Страница 156: ...Chapter 5 SNMP Commands Notification Log Commands 156 ...
Страница 164: ...Chapter 6 Remote Monitoring Commands 164 ...
Страница 218: ...Chapter 7 Authentication Commands Management IP Filter 218 ...
Страница 268: ...Chapter 8 General Security Measures Port based Traffic Segmentation 268 ...
Страница 292: ...Chapter 9 Access Control Lists ACL Information 292 ...
Страница 312: ...Chapter 10 Interface Commands Power Savings 312 ...
Страница 324: ...Chapter 11 Link Aggregation Commands Trunk Status Display Commands 324 ...
Страница 366: ...Chapter 15 Address Table Commands 366 ...
Страница 428: ...Chapter 17 VLAN Commands Configuring Voice VLANs 428 ...
Страница 572: ...Chapter 25 IP Interface Commands IPv6 Interface 572 ...
Страница 578: ...Section I Appendices 578 ...
Страница 594: ...Appendix C Customer Support Manuals 594 ...