Configuring A Static Ipv4 Source Guard Entry On An Interface - HP 5920 Series Configuration Manual

Hide thumbs Also See for 5920 Series:
Table of Contents

Advertisement

Dynamic IPv4 binding entries can contain such information as the MAC address, IPv4 address, VLAN
tag, ingress interface information, and entry type (such as DHCP snooping and DHCP relay). Which
information in an entry is used by IP source guard to filter IPv4 packets is determined by the IPv4 source
guard configuration on the interface:
If you bind both the source IP address and the source MAC address on the interface, the interface
forwards a received packet only when the packet's source IP address and source MAC address
both match a dynamic binding entry. If no match is found, the packet is dropped.
If you bind only the source IP address on the interface, the interface forwards a packet as long as
the packet's source IP address matches a dynamic binding entry. If no match is found, the packet is
dropped.
To implement dynamic IPv4 source guard, make sure the DHCP snooping or DHCP relay function works
normally on the network.
To enable the IPv4 source guard function on an interface:
Step
Enter system view.
1.
2.
Enter interface view.
3.
Enable the IPv4 source guard
function.

Configuring a static IPv4 source guard entry on an interface

Step
1.
Enter system view.
2.
Enter interface view.
3.
Configure a static IPv4
binding entry.
NOTE:
You cannot configure the same static binding entry on one interface, but you can configure the
same static binding entry on different interfaces.
For packet filtering on an interface, IP source guard ignores the VLAN information (if specified)
in static IPv4 source guard entries. To cooperate with ARP detection, you must specify the VLAN
where ARP detection is configured in static IPv4 source guard entries. Otherwise, ARP packets
will be discarded because they cannot match any static IPv4 entry. For more information about
the ARP detection function, see
Command
system-view
interface interface-type
interface-number
ip verify source ip-address
[ mac-address ]
Command
system-view
interface interface-type
interface-number
ip source binding ip-address
ip-address [ mac-address
mac-address ] [ vlan vlan-id ]
Security Configuration Guide
193
Remarks
N/A
These types of interfaces are
supported: Ethernet port and VLAN
interface.
By default, the function is disabled
on an interface.
Remarks
N/A
These types of interfaces are supported:
Ethernet interface and VLAN interface.
By default, no static IPv4 binding entry is
configured on an interface.
.

Advertisement

Table of Contents
loading

This manual is also suitable for:

5900 series

Table of Contents