Show Ip Verify Source - Cisco Catalyst 3750 Metro Command Reference Manual

Hide thumbs Also See for Catalyst 3750 Metro:
Table of Contents

Advertisement

Chapter 2 Catalyst 3750 Metro Switch Cisco IOS Commands

show ip verify source

Use the show ip verify source user EXEC command to display the IP source guard configuration on the
switch or on a specific interface.
Syntax Description
interface interface-id
Command Modes
User EXEC
Command History
Release
12.2(25)EY
Examples
This is an example of output from the show ip verify source command:
Switch> show ip verify source
Interface
---------
Fa1/0/1
Fa1/0/1
Fa1/0/2
Fa1/0/3
Fa1/0/4
Fa1/0/4
Fa1/0/4
Fa1/0/5
Fa1/0/5
In the previous example, this is the IP source guard configuration:
This is an example of output on an interface on which IP source guard is disabled:
Switch> show ip verify source fastethernet1/0/6
OL-9645-10
show ip verify source [interface interface-id]
(Optional) Display IP source guard configuration on a specific interface.
Modification
This command was introduced.
Filter-type
Filter-mode
-----------
-----------
ip
active
ip
active
ip
inactive-trust-port
ip
inactive-no-snooping-vlan
ip-mac
active
ip-mac
active
ip-mac
active
ip-mac
active
ip-mac
active
On the Fast Ethernet 1/0/1 interface, DHCP snooping is enabled on VLANs 10 to 20. For VLAN 10,
IP source guard with IP address filtering is configured on the interface, and a binding exists on the
interface. For VLANs 11 to 20, the second entry shows that a default port access control list (ACL)
is applied on the interface for the VLANs on which IP source guard is not configured.
The Fast Ethernet 1/0/2 interface is configured as trusted for DHCP snooping.
On the Fast Ethernet 1/0/3 interface, DHCP snooping is not enabled on the VLANs to which the
interface belongs.
On the Fast Ethernet 1/0/4 interface, IP source guard with source IP and MAC address filtering is
enabled, and static IP source bindings are configured on VLANs 10 and 11. For VLANs 12 to 20,
the default port ACL is applied on the interface for the VLANs on which IP source guard is not
configured.
On the Fast Ethernet 1/0/5 interface, IP source guard with source IP and MAC address filtering is
enabled and configured with a static IP binding, but port security is disabled. The switch cannot
filter source MAC addresses.
IP-address
Mac-address
---------------
--------------
10.0.0.1
deny-all
10.0.0.2
aaaa.bbbb.cccc
11.0.0.1
aaaa.bbbb.cccd
deny-all
deny-all
10.0.0.3
permit-all
deny-all
permit-all
Catalyst 3750 Metro Switch Command Reference
show ip verify source
Vlan
---------
10
11-20
10
11
12-20
10
11-20
2-511

Advertisement

Table of Contents
loading

Table of Contents