Chapter 17 Security Configuration
F
IGURE
37 IP S
OURCE
G
UARD
C
ONFIGURATION
IP Source Guard based on MAC address is configured on the
gei_1/2 interface mode. Afer getting IP address dynamically, PC
can only pass the data packet with source MAC address that is
local host NIC card.
Configuration of R1:
ZXR10(config)#ip dhcp snooping enable
ZXR10(config)#ip dhcp snooping vlan 100
ZXR10(config)#ip dhcp snooping trust gei_1/1
ZXR10(config)#interface gei_1/2
ZXR10(config-if)#ip dhcp snnoping ip-source-guard mac-base
IP Source Guard Configuration based on IP
Address and MAC address
In
Figure 38
, DHCP server connects gei_1/1 on R1, administra-
tor sets management DHCP, gei_1/1 belongs to vlan100. DHCP
Snooping function is enabled in VLAN100 and interface gei_1/1 is
configured as trusted. PC connects gei_1/2 of switch, which be-
longs to vlan100.
F
IGURE
38 IP S
OURCE
G
UARD
C
ONFIGURATION
IP Source Guard based on MAC address is configured on the
gei_1/2 interface mode. After getting IP address dynamically, PC
can only pass the data packet with source MAC address that is
local host NIC card and source IP address that is distributed by
DHCP server.
Configuration of R1:
ZXR10(config)#ip dhcp snooping enable
ZXR10(config)#ip dhcp snooping vlan 100
ZXR10(config)#ip dhcp snooping trust gei_1/1
ZXR10(config)#interface gei_1/2
ZXR10(config-if)#ip dhcp snnoping ip-source-guard mac-ip-base
Confidential and Proprietary Information of ZTE CORPORATION
173