Ip Source Guard Configuration Task List; Configuring The Ipv4 Source Guard Function; Enabling Ipv4 Source Guard On An Interface - HP 5920 Series Configuration Manual

Hide thumbs Also See for 5920 Series:
Table of Contents

Advertisement

Dynamic IPv6 source guard
IPv6 source guard on an interface obtains information from DHCPv6 snooping entries to generate IPv6
source guard binding entries for packet filtering.
For more information about DHCPv6 snooping, see Layer 3—IP Services Configuration Guide.

IP source guard configuration task list

To configure IPv4 source guard, perform the following tasks:
Tasks at a glance
(Required.)
(Optional.)
To configure IPv6 source guard, perform the following tasks:
Tasks at a glance
(Required.)
(Optional.)

Configuring the IPv4 source guard function

You cannot configure the IPv4 source guard function on a service loopback interface. If IPv4 source
guard is enabled on an interface, you cannot assign the interface to a service loopback group.

Enabling IPv4 source guard on an interface

You must first enable the IPv4 source guard function on an interface for the IP source guard to take effect.
All matching criteria in a static IPv4 source guard binding entry are used by IP source guard to filter
packets. For information about static binding entry configuration, see
guard binding
A dynamic IPv4 source guard binding entry can include MAC address, IPv4 address, VLAN tag, ingress
interface, and entry type. The entry type identifies the source module for the binding entry, such as DHCP
snooping and DHCP relay. Dynamic IP source guard uses the entries to filter incoming IPv4 packets
based on the matching criteria specified in the ip verify source command. If a match is found, the packet
is forwarded.
To implement dynamic IPv4 source guard, make sure the DHCP snooping or DHCP relay function
operates correctly on the network.
To enable the IPv4 source guard function on an interface:
Step
1.
Enter system view.
Enabling IPv4 source guard on an interface
Configuring a static IPv4 source guard binding entry
Enabling IPv6 source guard on an interface
Configuring a static IPv6 source guard binding entry
entry."
Command
system-view
316
"Configuring a static IPv4 source
Remarks
N/A

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

5900 series

Table of Contents