Chapter 9
| General Security Measures
IPv4 Source Guard
– 294 –
Default Setting
Mode: ACL, Maximum Binding: 5
Mode: MAC, Maximum Binding: 16
Command Mode
Interface Configuration (Ethernet)
Command Usage
◆
This command sets the maximum number of address entries that can be
mapped to an interface in the binding table for the specified mode (ACL
binding table or MAC address table) including dynamic entries discovered
by DHCP snooping and static entries set by the
command.
◆
The maximum binding for ACL mode restricts the number of “active”
entries per port. If binding entries exceed the maximum number in IP
source guard, only the maximum number of binding entries will be set.
Dynamic binding entries exceeding the maximum number will be created
but will not be active.
◆
The maximum binding for MAC mode restricts the number of MAC
addresses learned per port. Authenticated IP traffic with different source
MAC addresses cannot be learned if it would exceed this maximum
number.
Example
This example sets the maximum number of allowed entries in the binding table
for port 5 to one entry. The mode is not specified, and therefore defaults to the
ACL binding table.
Console(config)#interface ethernet 1/5
Console(config-if)#ip source-guard max-binding 1
Console(config-if)#
ip source-guard mode
This command sets the source-guard learning mode to search for addresses
in the ACL binding table or the MAC address binding table. Use the
no
form to
restore the default setting.
Syntax
ip source-guard mode
{
acl
|
mac
}
no
ip source-guard
mode
mode
- Specifies the learning mode.
acl
- Searches for addresses in the ACL binding table.
mac
- Searches for addresses in the MAC address binding table.
Содержание SC30010
Страница 1: ...C 300 Series Gigabit Managed Switch CLI Reference Guide SOFTWARE RELEASE V1 1 10 171 www signamax com ...
Страница 2: ...CLI Reference Guide SC30010 C 300 48 Port Gigabit Managed Switch E122017 KS R01 ...
Страница 482: ...Chapter 19 Class of Service Commands Priority Commands Layer 3 and 4 482 ...
Страница 670: ......
Страница 671: ...E122017 KS R01 ...