Example For Configuring Ip Source Trail - Huawei Quidway S9300 Configuration Manual

Terabit routing switch
Table of Contents

Advertisement

Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
Procedure
Step 1 Enable the IP source guard function.
# Enable the IP source guard function on GE 1/0/1 connected to Host A.
[Quidway] interface gigabitethernet 1/0/1
[Quidway-GigabitEthernet1/0/1] ip source check user-bind enable
[Quidway-GigabitEthernet1/0/1] ip source check user-bind check-item ip-address mac-
address
[Quidway-GigabitEthernet1/0/1] quit
# Enable the IP source guard function on GE 1/0/2 connected to Host B.
[Quidway] interface gigabitethernet 1/0/2
[Quidway-GigabitEthernet1/0/2] ip source check user-bind enable
[Quidway-GigabitEthernet1/0/2] ip source check user-bind check-item ip-address mac-
address
[Quidway-GigabitEthernet1/0/2] quit
Step 2 Configure the check items of the static binding table.
# Configure Host A in the static binding table.
[Quidway] user-bind static ip-address 10.0.0.1 mac-address 0001-0001-0001
interface gigabitethernet 1/0/1 vlan 10
Step 3 Verify the configuration.
Run the display user-bind all command on the S9300 to view information about the binding
table.
<Quidway> display user-bind all
bind-table:
ifname
-------------------------------------------------------------------------------
GE1/0/1
-------------------------------------------------------------------------------
Static binditem count:
The preceding information indicates that Host A exists in the static binding table, whereas Host
B does not exist.
----End
Configuration Files
#
sysname Quidway
#
user-bind static ip-address 10.0.0.1 mac-address 0001-0001-0001 interface
GigabitEthernet 1/0/1 vlan 10
#
interface GigabitEthernet 1/0/1
ip source check user-bind enable
ip source check user-bind check-item ip-address mac-address
#
interface GigabitEthernet 1/0/2
ip source check user-bind enable
ip source check user-bind check-item ip-address mac-address
#
return

5.7.2 Example for Configuring IP Source Trail

Issue 06 (2010–01–08)
vsi O/I-vlan mac-address
--
10/ --
0001-0001-0001 10.0.0.1
1
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
5 Source IP Attack Defense Configuration
ip-address
tp lease
S
0
Static binditem total count:
1
5-15

Advertisement

Table of Contents
loading

Table of Contents