Configuring an ike proposal, Ip source guard configuration examples, Static ipv4 source guard configuration example – H3C Technologies H3C S12500-X Series Switches User Manual
Page 223
211
Task Command
Display IPv4 source guard
binding entries (in IRF
mode).
display ip source binding [ static | [ vpn-instance vpn-instance-name ]
[ dhcp-relay | dhcp-server | dhcp-snooping ] ] [ ip-address ip-address ]
[ mac-address mac-address ] [ vlan vlan-id ] [ interface interface-type
interface-number ] [ chassis chassis-number slot slot-number ]
For IPv6 source guard:
Task Command
Display static IPv6 source
guard binding entries (in
standalone mode).
display ipv6 source binding static [ ip-address ipv6-address ] [ mac-address
mac-address ] [ vlan vlan-id ] [ interface interface-type interface-number ] [ slot
slot-number ]
Display static IPv6 binding
entries (in IRF mode).
display ipv6 source binding static [ ip-address ipv6-address ] [ mac-address
mac-address ] [ vlan vlan-id ] [ interface interface-type interface-number ]
[ chassis chassis-number slot slot-number ]
130B
IP source guard configuration examples
294B
Static IPv4 source guard configuration example
514B
Network requirements
As shown in
914H
Figure 64
, Host A is connected to Ten-GigabitEthernet 1/0/2 of Switch B. Host B is
connected to Ten-GigabitEthernet 1/0/1 of Switch B. Host C is connected to Ten-GigabitEthernet 1/0/2
of Switch A. Switch B is connected to Ten-GigabitEthernet 1/0/1 of Switch A. All hosts use static IP
addresses.
Configure static IPv4 source guard binding entries on Switch A and Switch B to meet the following
requirements:
•
Ten-GigabitEthernet 1/0/2 of Switch A allows only IP packets from Host C to pass.
•
Ten-GigabitEthernet 1/0/1 of Switch A allows only IP packets from Host A to pass.
•
All interfaces of Switch B allow IP packets from Host A to pass.
•
Ten-GigabitEthernet 1/0/1 of Switch B allows IP packets from Host B to pass.
Figure 64 Network diagram