Chapter 4 Service Configuration
Command Mode
Global configuration mode
Syntax
set dhcp ip-source-guard
{{
add
|
delete
}
port
<
portlist
>|
quota
<
0-400
>}
Parameters
Parameter
Description
add
Enables the ip-source-guard function.
delete
Disables the ip-source-guard function.
<
portlist
>
Port list.
quota
Quota of source addresses.
<
0-400
>
The value 0 means no limit. The source IP addresses include
IPv4 addresses and IPv6 addresses.
Guidelines
After the ip-source-guard function is enabled, by listening the interactions between the
client and server, the IP addresses allocated by the server to the client are recorded and
the messages with other source IP addresses are filtered to prevent spoofing.
Before enabling the ip-source-guard function, you must enable the DHCP snooping
function.
Example
The following example enables the ip-source-guard function for ports 9 and 10:
zte(cfg)#set dhcp ip-source-guard add port 9-10
Fail to enable ip source guard on port 9.
%
DHCP snooping is disabled on this port (0x40000cea)
zte(cfg)#set dhcp snooping add port 9
zte(cfg)#set dhcp ip-source-guard add port 9-10
4.25.6 set dhcp snooping bind-entry mac ip vlan port
Purpose
This command adds the static user information binding entry.
Command Mode
Global configuration mode
4-433
SJ-20130731155059-003|2013-11-27 (R1.0)
ZTE Proprietary and Confidential