Configuring A Static Ipv4 Source Guard Entry - HP 10500 Series Configuration Manual

Security configuration guide
Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

NOTE:
Although dynamic IPv4 source guard entries are generated based on DHCP entries, the number of
dynamic IPv4 source guard entries is not necessarily the same as that of the DHCP entries.

Configuring a static IPv4 source guard entry

Static IPv4 binding entries take effect only on the ports configured with the IPv4 source guard function
(see
"Enabling IPv4 source guard on a
Port-based static IPv4 source guard entries and dynamic IPv4 source guard entries take precedence over
global static IPv4 source guard entries. A port matches a packet against global static binding entries only
when the packet does not match any port-based static binding entry or dynamic binding entry on the
port.
Follow these guidelines to configure a static IPv4 source guard entry:
You cannot configure the same static binding entry on one port, but you can configure the same
static entry on different ports.
When the ARP detection function is configured, be sure to specify the VLAN where ARP detection
is configured in static IPv4 binding entries. Otherwise, ARP packets are discarded because they
cannot match any static IPv4 binding entry.
If a static binding entry to be added denotes the same binding as an existing dynamic binding entry,
the new static binding entry overwrites the dynamic binding entry.
Configuring global static IPv4 binding entries
A global static binding entry defines the IP address and MAC address of the packets that can be
forwarded by ports. It takes effect on all ports of the device.
NOTE:
This feature is available in only Release 1203 and later.
To configure a global static IPv4 binding entry:
Step
1.
Enter system view.
2.
Configure a global static IPv4
binding entry.
Configuring port-based static IPv4 binding entries
Step
1.
Enter system view.
2.
Enter Layer 2 Ethernet
interface view.
port").
Command
system-view
ip source binding ip-address
ip-address mac-address
mac-address
Command
system-view
interface interface-type
interface-number
239
Remarks
N/A
No global static IPv4 binding entry
is configured by default.
Remarks
N/A
N/A

Advertisement

Table of Contents
loading

Table of Contents