Ipsg Configuration Examples; Static Ipv4Sg Configuration Example - HPE FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Task
(In IRF mode.) Display
IPv6 address bindings.
(In standalone mode.)
Display IPv6SG address
bindings.
(In IRF mode.) Display
IPv6 address bindings.

IPSG configuration examples

Static IPv4SG configuration example

Network requirements
As shown in
Configure static IPv4SG bindings on Device A and Device B to meet the following requirements:
GigabitEthernet 1/0/2 of Device A allows only IP packets from Host C to pass.
GigabitEthernet 1/0/1 of Device A allows only IP packets from Host A to pass.
All interfaces of Device B allow IP packets from Host A to pass.
GigabitEthernet 1/0/1 of Device B allows IP packets from Host B to pass.
Figure 130 Network diagram
GE1/0/2
Host A
IP: 192.168.0.1/24
MAC: 0001-0203-0406
Configuration procedure
1.
Configure Device A:
# Configure IP addresses for the interfaces. (Details not shown.)
# Enable IPv4SG on GigabitEthernet 1/0/2.
<DeviceA> system-view
[DeviceA] interface gigabitethernet 1/0/2
[DeviceA-GigabitEthernet1/0/2] ip verify source ip-address mac-address
# On GigabitEthernet 1/0/2, configure a static IPv4SG binding for Host C.
[DeviceA-GigabitEthernet1/0/2] ip source binding ip-address 192.168.0.3 mac-address
0001-0203-0405
Command
display ipv6 source binding [ static | [ vpn-instance vpn-instance-name ]
[ dhcpv6-relay | dhcpv6-snooping | nd-snooping ] ] [ ip-address
ipv6-address ] [ mac-address mac-address ] [ vlan vlan-id ] [ interface
interface-type interface-number ] [ chassis chassis-number slot slot-number ]
display ipv6 source binding pd [ vpn-instance vpn-instance-name ] [ prefix
prefix/prefix-length ] [ mac-address mac-address ] [ vlan vlan-id ] [ interface
interface-type interface-number ] [ slot slot-number ]
display ipv6 source binding pd [ vpn-instance vpn-instance-name ] [ prefix
prefix/prefix-length ] [ mac-address mac-address ] [ vlan vlan-id ] [ interface
interface-type interface-number ] [ chassis chassis-number slot slot-number ]
Figure
130, all hosts use static IP addresses.
GE1/0/1
Device A
GE1/0/1
Device B
Host B
IP: 192.168.0.2/24
MAC: 0001-0203-0407
GE1/0/2
Host C
IP: 192.168.0.3/24
MAC : 0001-0203-0405
503

Advertisement

Table of Contents
loading

Table of Contents