Ip Source Binding - HP 5920 Command Reference Manual

Table of Contents

Advertisement

Related commands
ipv6 source binding
ipv6 verify source

ip source binding

Use ip source binding to configure a static IPv4 source guard entry.
Use undo ip source binding to delete the static IPv4 source guard entries configured on the interface.
Syntax
ip source binding ip-address ip-address [ mac-address mac-address ] [ vlan vlan-id ]
undo ip source binding ip-address ip-address [ mac-address mac-address ] [ vlan vlan-id ]
Default
No static IPv4 source guard entry is configured on an interface.
Views
Ethernet interface view, VLAN interface view
Predefined user roles
network-admin
Parameters
ip-address ip-address: Specifies an IPv4 address for the static entry. The IPv4 address must be a class A,
B, or C address, and cannot be 127.x.x.x, 0.0.0.0, or a multicast IP address.
mac-address mac-address: Specifies a MAC address for the static entry. The MAC address must be in
H-H-H format, and cannot be all 0s, all Fs (a broadcast address), or a multicast address.
vlan vlan-id: Specifies a VLAN ID for the static entry. The value range is 1 to 4094.
Usage guidelines
Static IPv4 source guard entries on an interface filter IPv4 packets received by the interface or check user
validity by cooperating with the ARP detection feature.
For packet filtering on an interface, IP source guard ignores the VLAN information (if specified) in static
IPv4 source guard entries. To cooperate with ARP detection, you must specify the VLAN where ARP
detection is configured in static IPv4 source guard entries. Otherwise, ARP packets will be discarded
because they cannot match any static IPv4 entry. For more information about the ARP detection function,
see Security Configuration Guide.
You cannot configure static IPv4 source guard entries on an interface that is in a service loopback group.
Examples
# On interface Ten-GigabitEthernet 1/0/1, configure a static IPv4 source guard entry to allow only the
packets whose source IP address is 192.168.0.1 and source MAC address is 0001-0001-0001 to pass.
<Sysname> system-view
[Sysname] interface ten-gigabitEthernet 1/0/1
283

Advertisement

Table of Contents
loading

This manual is also suitable for:

59005920 series5900 series

Table of Contents