Ip source-guard – Microsens MS453490M Management Guide User Manual

Page 670

Advertising
background image

C

HAPTER

25

| General Security Measures

IP Source Guard

– 670 –

All static entries are configured with an infinite lease time, which is

indicated with a value of zero by the

show ip source-guard

command

(

page 672

).

When source guard is enabled, traffic is filtered based upon dynamic

entries learned via DHCP snooping, or static addresses configured in

the source guard binding table with this command.

Static bindings are processed as follows:

If there is no entry with same VLAN ID and MAC address, a new

entry is added to binding table using the type of static IP source

guard binding.

If there is an entry with same VLAN ID and MAC address, and the

type of entry is static IP source guard binding, then the new entry

will replace the old one.

If there is an entry with same VLAN ID and MAC address, and the

type of the entry is dynamic DHCP snooping binding, then the new

entry will replace the old one and the entry type will be changed to

static IP source guard binding.

E

XAMPLE

This example configures a static source-guard binding on port 5.

Console(config)#ip source-guard binding 11-22-33-44-55-66 vlan 1 192.168.0.99

interface ethernet 1/5

Console(config-if)#

R

ELATED

C

OMMANDS

ip source-guard (670)

ip dhcp snooping (661)

ip dhcp snooping vlan (665)

ip source-guard

This command configures the switch to filter inbound traffic based source

IP address, or source IP address and corresponding MAC address. Use the

no form to disable this function.

S

YNTAX

ip source-guard {sip | sip-mac}
no ip source-guard

sip - Filters traffic based on IP addresses stored in the binding

table.
sip-mac - Filters traffic based on IP addresses and corresponding

MAC addresses stored in the binding table.

D

EFAULT

S

ETTING

Disabled

Advertising