Ipsg Configuration Examples; Static Ipv4Sg Configuration Example - HPE FlexNetwork 7500 Series Security Configuration Manual

Table of Contents

Advertisement

Task
(In standalone mode.)
Display source items that
have been configured to
be excluded from IPSG
filtering.
(In IRF mode.) Display
source items that have
been configured to be
excluded from IPSG
filtering.
(In standalone mode.)
Display IPv6SG bindings.
(In IRF mode.) Display
IPv6 bindings.

IPSG configuration examples

Static IPv4SG configuration example

Network requirements
As shown in
Configure static IPv4SG bindings on Device A and Device B to meet the following requirements:
GigabitEthernet 1/0/2 of Device A allows only IP packets from Host C to pass.
GigabitEthernet 1/0/1 of Device A allows only IP packets from Host A to pass.
All interfaces of Device B allow IP packets from Host A to pass.
GigabitEthernet 1/0/1 of Device B allows IP packets from Host B to pass.
Figure 115 Network diagram
GE1/0/2
Host A
IP: 192.168.0.1/24
MAC: 0001-0203-0406
Configuration procedure
1.
Configure Device A:
# Configure IP addresses for the interfaces. (Details not shown.)
# Enable IPv4SG on GigabitEthernet 1/0/2.
Command
display ip verify source excluded [ vlan start-vlan-id [ to end-vlan-id ] ] [ slot
slot-number ]
display ip verify source excluded [ vlan start-vlan-id [ to end-vlan-id ] ]
[ chassis chassis-number slot slot-number ]
display ipv6 source binding [ static | [ vpn-instance vpn-instance-name ]
[ dhcpv6-relay | dhcpv6-snooping | nd-snooping ] ] [ ip-address
ipv6-address ] [ mac-address mac-address ] [ vlan vlan-id ] [ interface
interface-type interface-number ] [ slot slot-number ]
display ipv6 source binding [ static | [ vpn-instance vpn-instance-name ]
[ dhcpv6-relay | dhcpv6-snooping | nd-snooping ] ] [ ip-address
ipv6-address ] [ mac-address mac-address ] [ vlan vlan-id ] [ interface
interface-type interface-number ] [ chassis chassis-number slot slot-number ]
Figure
115, all hosts use static IP addresses.
GE1/0/1
Device A
GE1/0/1
Device B
Host B
IP: 192.168.0.2/24
MAC: 0001-0203-0407
GE1/0/2
Host C
IP: 192.168.0.3/24
MAC : 0001-0203-0405
408

Advertisement

Table of Contents
loading

Table of Contents