Configuring an ike proposal, Ip source guard configuration examples, Static ipv4 source guard configuration example – H3C Technologies H3C S12500-X Series Switches User Manual

Page 223

Advertising
background image

211

Task Command

Display IPv4 source guard
binding entries (in IRF
mode).

display ip source binding [ static | [ vpn-instance vpn-instance-name ]
[ dhcp-relay | dhcp-server | dhcp-snooping ] ] [ ip-address ip-address ]

[ mac-address mac-address ] [ vlan vlan-id ] [ interface interface-type

interface-number ] [ chassis chassis-number slot slot-number ]

For IPv6 source guard:

Task Command

Display static IPv6 source
guard binding entries (in

standalone mode).

display ipv6 source binding static [ ip-address ipv6-address ] [ mac-address
mac-address ] [ vlan vlan-id ] [ interface interface-type interface-number ] [ slot

slot-number ]

Display static IPv6 binding
entries (in IRF mode).

display ipv6 source binding static [ ip-address ipv6-address ] [ mac-address
mac-address ] [ vlan vlan-id ] [ interface interface-type interface-number ]
[ chassis chassis-number slot slot-number ]

130B

IP source guard configuration examples

294B

Static IPv4 source guard configuration example

514B

Network requirements

As shown in

914H

Figure 64

, Host A is connected to Ten-GigabitEthernet 1/0/2 of Switch B. Host B is

connected to Ten-GigabitEthernet 1/0/1 of Switch B. Host C is connected to Ten-GigabitEthernet 1/0/2

of Switch A. Switch B is connected to Ten-GigabitEthernet 1/0/1 of Switch A. All hosts use static IP
addresses.
Configure static IPv4 source guard binding entries on Switch A and Switch B to meet the following

requirements:

Ten-GigabitEthernet 1/0/2 of Switch A allows only IP packets from Host C to pass.

Ten-GigabitEthernet 1/0/1 of Switch A allows only IP packets from Host A to pass.

All interfaces of Switch B allow IP packets from Host A to pass.

Ten-GigabitEthernet 1/0/1 of Switch B allows IP packets from Host B to pass.

Figure 64 Network diagram

Advertising