Configuring The Ip Source Guard; Table 14-7 Configuration Data Of Ip Source Guard - Zte ZXA10 C300 Configuration Manual

Optical access convergence equipment
Hide thumbs Also See for ZXA10 C300:
Table of Contents

Advertisement

ZXA10 C300 Configuration Manual (CLI)
Svlan
-------------
300
– End of Steps –

14.5 Configuring the IP Source Guard

The IP source guard based on the service port prevents illegal users from accessing the
Internet.
Context
IP source guard supports IP/MAC anti-spoofing and access security management based
on the service port.
The ZXA10 C300 supports IP source guard on both IPv4 and IPv6.
l
The legal IPv4 subscribers are managed through either the DHCP snooping table or
static IP addresses.
l
The legal IPv6 subscribers are managed through either the NDP snooping/DHCPv6
snooping, or static IP addresses.
Configuration Data
Table 14-7

Table 14-7 Configuration Data of IP Source Guard

Item
Global IP source guard
Interface IP source guard
Maximum IP address number
IPv4 DHCP snooping static binding
IPv6 DHCP snooping static binding
Steps
1. Enable the IP source guard function.
ZXAN(config)#ip-source-guard enable
2. In GPON-ONU interface mode, configure the maximum IPv4 and IPv6 subscriber
binding entries on the ONU interface.
SJ-20130520164529-007|2013-06-30 (R1.0)
Cvlan
200
lists the configuration data of the IP source guard.
Data
Enable
l
Interface: gpon-onu_1/5/1:2 (virtual port 1)
l
Service port: 1
l
IP source guard: enable
l
IPv4: 2
l
IPv6: 4
IP address: 1.1.1.1
l
IPv6 address: 2001::ff01
l
IPv6-mask: 128
l
MAC address: 2365.1498.2369
14-12
ZTE Proprietary and Confidential

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents