enable source-ip-lockdown ports
enable source-ip-lockdown ports [all | <portlist>]
From ExtremeWare 7.7, this command is modified to:
enable ip-security source-ip-lockdown ports [all | <portlist>]
Description
Enables the source IP lockdown feature.
Syntax Description
port-list
Specifies one or more ports for which source IP lockdown should be enabled.On a modular switch, can
be a list of slots and ports. On a stand-alone switch, can be one or more port numbers. May be in the
form 1, 2, 3-5, 1:*, 1:5, 1:6-1:8.
all
Specifies all ports.
Default
By default source IP lockdown is disabled.
Usage Guidelines
This feature applies only to the Layer 3 environment. The switch allows only those hosts whose IP
addresses are assigned by the locally configured DHCP server (switch acting as a DHCP server) or
assigned by an external DHCP server. In the latter case, the switch should be configured as a bootp
relay. For statically configured IP ARP entries, the MAC address (specified during the addition of a IP
ARP entry) should already exist in the FDB. Before enabling source IP lockdown on a port, the switch
should be configured either as a DHCP Server or a BOOTP Relay.
Example
The following command enables source IP lockdown on ports 3 and 5
enable source-ip-lockdown ports 3,5
History
This command was first available in ExtremeWare 7.4.
This command is modifed in ExtremeWare 7.7.0. The new command is:
enable ip-security source-ip-lockdown ports
Both the commands can be used in ExtremeWare 7.7.0.
Platform Availability
This command is available on all platforms
ExtremeWare 7.7 Command Reference Guide
[all | <portlist>]
enable source-ip-lockdown ports
1041