Ip Verify Source - HP 6125XLG Command Reference Manual

Blade switch security command reference
Table of Contents

Advertisement

Syntax
ip source binding ip-address ip-address [ mac-address mac-address ] [ vlan vlan-id ]
undo ip source binding ip-address ip-address [ mac-address mac-address ] [ vlan vlan-id ]
Default
No static IPv4 source guard binding entry is configured on an interface.
Views
Ethernet interface view, VLAN interface view
Predefined user roles
network-admin
Parameters
ip-address ip-address: Specifies an IPv4 address for the static entry. The IPv4 address must be a class A,
B, or C address, and cannot be 127.x.x.x, 0.0.0.0, or a multicast IP address.
mac-address mac-address: Specifies a MAC address for the static entry. The MAC address must be in
H-H-H format, and cannot be all 0s, all Fs (a broadcast address), or a multicast address.
vlan vlan-id: Specifies a VLAN ID for the static entry. The value range is 1 to 4094. This option is
supported in only Ethernet interface view.
Usage guidelines
Static IPv4 source guard binding entries on an interface filter IPv4 packets received by the interface or
check user validity by cooperating with the ARP detection feature.
For packet filtering on an interface, IP source guard ignores the VLAN information (if specified) in static
IPv4 source guard binding entries. To cooperate with ARP detection, you must specify the VLAN where
ARP detection is configured in static IPv4 source guard binding entries. Otherwise, ARP packets will be
discarded because they cannot match any static IPv4 entry. For more information about the ARP
detection function, see Security Configuration Guide.
You cannot configure static IPv4 source guard binding entries on an interface that is in a service
loopback group.
Examples
# On interface Ten-GigabitEthernet 1/1/5, configure a static IPv4 source guard binding entry to allow
only the packets whose source IP address is 192.168.0.1 and source MAC address is 0001-0001-0001 to
pass.
<Sysname> system-view
[Sysname] interface ten-gigabitEthernet 1/1/5
[Sysname-Ten-GigabitEthernet1/1/5] ip source binding ip-address 192.168.0.1 mac-address
0001-0001-0001
Related commands
display ip source binding

ip verify source

Use ip verify source to enable the IPv4 source guard function.
Use undo ip verify source to restore the default.
200

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents