Dynamic Ipv4 Source Guard Using Dhcp Snooping - HP 10500 Series Configuration Manual

Security configuration guide
Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

[DeviceB-GigabitEthernet1/0/2] ip source binding ip-address 192.168.0.1 mac-address
0001-0203-0406
[DeviceB-GigabitEthernet1/0/2] quit
# Enable the IPv4 source guard function on GigabitEthernet 1/0/1.
[DeviceB] interface gigabitethernet 1/0/1
[DeviceB-GigabitEthernet1/0/1] ip verify source ip-address
# Configure GigabitEthernet 1/0/1 to allow only IP packets with the source IP address of
192.168.0.2 to pass.
[DeviceB-GigabitEthernet1/0/1] ip source binding ip-address 192.168.0.2
[DeviceB-GigabitEthernet1/0/1] quit
Verifying the configuration
# On Device A, display information about static IPv4 source guard entries. The output shows that the
static IPv4 source guard entries are configured successfully.
[DeviceA] display ip source binding static
Total entries found: 2
MAC Address
0001-0203-0405
0001-0203-0406
# On Device B, display information about static IPv4 source guard entries. The output shows that the
static IPv4 source guard entries are configured successfully.
[DeviceB] display ip source binding static
Total entries found: 2
MAC Address
0001-0203-0406
N/A

Dynamic IPv4 source guard using DHCP snooping

Network requirements
As shown in
GigabitEthernet 1/0/1 and GigabitEthernet 1/0/2, respectively. The host obtains an IP address from
the DHCP server.
Enable DHCP snooping on the device to record the DHCP snooping entry of the host. Enable the IPv4
source guard function on the device's port GigabitEthernet 1/0/1 to filter packets based on the DHCP
snooping entry, allowing only packets from clients that obtain IP addresses through the DHCP server to
pass.
For information about DHCP server configuration, see Layer 3—IP Services Configuration Guide.
Figure 94 Network diagram
IP Address
192.168.0.3
192.168.0.1
IP Address
192.168.0.1
192.168.0.2
Figure
94, the device connects to the host (client) and the DHCP server through ports
VLAN
Interface
N/A
GE1/0/2
N/A
GE1/0/1
VLAN
Interface
N/A
GE1/0/2
N/A
GE1/0/1
245
Type
Static
Static
Type
Static
Static

Advertisement

Table of Contents
loading

Table of Contents