Configuring Ipv4 Source Guard Binding - HP 5120 EI Switch Series Configuration Manual

Hide thumbs Also See for 5120 EI Switch Series:
Table of Contents

Advertisement

Figure 76 Network diagram for excluded port application in IP source guard global static binding
192.168.0.1/24
Src MAC
0001-0203-0406
VLAN 10
Host A
IP: 192.168.0.2/24
MAC: 0001-0203-0406
Gateway: 192.168.0.1/24
NOTE:
After you configure IPv4 or IPv6 global static binding entries on a switch, configure the uplink port of
the switch as an excluded port of global static binding to ensure packet forwarding between VLANs.
Dynamic IP source guard binding
Dynamic IP source guard entries are generated dynamically according to client entries on the DHCP
snooping or DHCP relay agent device. They are suitable for scenarios where many hosts reside on a LAN
and obtain IP addresses through DHCP. Once DHCP allocates an IP address to a client, IP source guard
automatically adds the client entry to allow the client to access the network. A user using an IP address
not obtained through DHCP cannot access the network. Dynamic IPv6 source guard entries can also be
obtained from client entries on the ND snooping device.
Dynamic IPv4 source guard binding generates IPv4 source guard binding entries dynamically based
on DHCP snooping or DHCP relay entries to filter IPv4 packets received on a port.
Dynamic IPv6 source guard binding generates IPv6 source guard binding entries dynamically based
on DHCPv6 snooping or ND snooping entries to filter IPv6 packets received on a port.
NOTE:
For information about DHCP snooping and DHCP relay, see the
For information about DHCPv6 snooping, see the
For information about ND snooping, see the

Configuring IPv4 source guard binding

NOTE:
You cannot configure the IP source guard function on a port in an aggregation group, nor can you add
a port configured with IP source guard to an aggregation group.
Device A
Vlan-int10
Vlan-int20
192.168.1.1/24
Src MAC
0001-0202-0202
Src IP
192.168.0.2
GE1/0/1
Device B
IP: 192.168.1.2/24
MAC: 0001-0203-0407
Gateway: 192.168.1.1/24
Src IP
192.168.0.2
Global static binding entires
MAC
IP
0001-0203-0406
192.168.0.2
0001-0203-0407
192.168.1.2
VLAN 20
Host B
Layer 3—IP Services Configuration Guide
Layer 3—IP Services Configuration Guide
Layer 3—IP Services Configuration Guide
251
.
.
.

Advertisement

Table of Contents
loading

Table of Contents