Configuring A Static Ipv4 Source Guard Binding Entry On An Interface - HP 6125XLG Configuration Manual

Blade switch security configuration guide
Table of Contents

Advertisement

All the fields in a static IPv4 binding entry are used by IP source guard to filter packets. For information
about how to configure a static IPv4 binding entry, see
entry on an
Dynamic IPv4 binding entries can contain such information as the MAC address, IPv4 address, VLAN
tag, ingress interface information, and entry type (such as DHCP snooping and DHCP relay). Which
information in an entry is used by IP source guard to filter IPv4 packets is determined by the IPv4 source
guard configuration on the interface:
If you bind both the source IP address and the source MAC address on the interface, the interface
forwards a received packet only when the packet's source IP address and source MAC address
both match a dynamic binding entry. If no match is found, the packet is dropped.
If you bind only the source IP address on the interface, the interface forwards a packet as long as
the packet's source IP address matches a dynamic binding entry. If no match is found, the packet is
dropped.
To implement dynamic IPv4 source guard, make sure the DHCP snooping or DHCP relay function
operate correctly on the network.
To enable the IPv4 source guard function on an interface:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Enable the IPv4 source guard
function.
Configuring a static IPv4 source guard binding entry on an
interface
Step
1.
Enter system view.
2.
Enter interface view.
3.
Configure a static IPv4
binding entry.
interface."
Command
system-view
interface interface-type
interface-number
ip source binding ip-address
ip-address [ mac-address
mac-address ] [ vlan vlan-id ]
"Configuring a static IPv4 source guard binding
Command
system-view
interface interface-type
interface-number
ip verify source ip-address
[ mac-address ]
163
Remarks
N/A
These types of interfaces are
supported: Ethernet port and VLAN
interface.
By default, the function is disabled
on an interface.
Remarks
N/A
These types of interfaces are supported:
Ethernet interface and VLAN interface.
By default, no static IPv4 binding entry is
configured on an interface.
The vlan vlan-id option is supported in only
Ethernet interface view.

Advertisement

Table of Contents
loading

Table of Contents