Configuring The Dynamic Ip Source Guard Binding Function; Displaying And Maintaining Ip Source Guard - H3C S9500E Series Security Configuration Manual

Routing switches
Hide thumbs Also See for S9500E Series:
Table of Contents

Advertisement

Configuring the dynamic IP source guard
binding function
After the dynamic IP source guard binding function is enabled on a port, IP source guard will
obtain binding entries dynamically through cooperation with DHCP protocols.
Cooperating with DHCP snooping, IP source guard will automatically obtain the DHCP
snooping entries that are generated during dynamic IP address allocation on an Ethernet
port.
Cooperating with DHCP Relay, IP source guard will automatically obtain the DHCP Relay
entries that are generated during dynamic IP address allocation across network segments on
a VLAN interface.
Dynamic IP source guard entries can contain such information as MAC address, IP address, VLAN
tag, ingress port information, and entry type (DHCP snooping or DHCP relay). IP source guard
applies these binding entries to the port, so that the port can filter packets accordingly.
Follow these steps to configure the dynamic IP source guard binding function:
To do...
1.
Enter system view
2.
Enter interface view
3.
Configure the dynamic IP
source guard binding function
The dynamic binding function can be configured on Ethernet interfaces and VLAN interfaces.
If you configure dynamic IP source guard binding on a port for multiple times, the last configuration will
overwrite the previous configuration on the port.

Displaying and maintaining IP source guard

To do...
1.
Display information about static
IP source guard binding entries
2.
Display information about
dynamic IP source guard
binding entries on a switch in
standalone mode
3.
Display information about
dynamic IP source guard
binding entries on a switch in
IRF mode
Use the command...
system-view
interface interface-type interface-
number
ip check source { ip-address
| ip-address mac-address |
mac-address }
Use the command...
display user-bind [ interface interface-type
interface-number | ip-address ip-address |
mac-address mac-address ]
display ip check source [ interface
interface-type interface-number | ip-address
ip-address | mac-address mac-address ] [
slot slot-number ]
display ip check source [ interface
interface-type interface-number | ip-address
ip-address | mac-address mac-address ] [
chassis chassis-number slot slot-number ]
155
Remarks
Required
Not configured by default
Remarks
Available in any view
Available in any view
Available in any view

Advertisement

Table of Contents
loading

Table of Contents