C
ONFIGURING
THE
S
WITCH
3-238
When enabled, traffic is filtered based upon dynamic entries learned via
DHCP snooping or static addresses configured in the source guard
binding table. An inbound packet’s IP address (sip option) or both its IP
address and corresponding MAC address (sip-mac option) are checked
against the binding table. If no matching entry is found, the packet is
dropped.
Command Attributes
•
Filter Type
– Configures the switch to filter inbound traffic based
source IP address, or source IP address and corresponding MAC
address. (Default: None)
-
None
– Disables IP source guard filtering on the port.
-
SIP
– Enables traffic filtering based on IP addresses stored in the
binding table.
-
SIP-MAC
– Enables traffic filtering based on IP addresses and
corresponding MAC addresses stored in the binding table.
Web
– Click IP Source Guard, Port Configuration.
Figure 3-111. IP Source Guard Port Configuration
Содержание 6128L2
Страница 2: ......
Страница 21: ...CONTENTS xvii Glossary Index ...
Страница 22: ...CONTENTS xviii ...
Страница 26: ...TABLES xxii ...
Страница 40: ...INTRODUCTION 1 10 ...
Страница 54: ...INITIAL CONFIGURATION 2 14 ...
Страница 193: ...PORT CONFIGURATION 3 139 Figure 3 61 Displaying Etherlike and RMON Statistics ...
Страница 257: ...QUALITY OF SERVICE 3 203 Figure 3 90 Configuring Policy Maps ...
Страница 313: ...COMMAND GROUPS 4 13 PE Privileged Exec VC VLAN Database Configuration ...
Страница 592: ...TROUBLESHOOTING B 4 ...
Страница 605: ......