Configuring Ip Source Guard For Static Hosts; Configuring Ip Source Guard For Static Hosts On A Layer 2 Access Port - Cisco Catalyst 2975 Software Configuration Manual

Ios release 12.2(55)se
Hide thumbs Also See for Catalyst 2975:
Table of Contents

Advertisement

Chapter 20
Configuring DHCP Features and IP Source Guard Features
Switch(config-if)# exit
Switch(config)# ip source binding 0100.0022.0010 vlan 10 10.0.0.2 interface
gigabitethernet1/0/1
Switch(config)# ip source binding 0100.0230.0002 vlan 11 10.0.0.4 interface
gigabitethernet1/0/1
Switch(config)# end

Configuring IP Source Guard for Static Hosts

Configuring IP Source Guard for Static Hosts on a Layer 2 Access Port

You must configure the ip device tracking maximum limit-number interface configuration command
Note
globally for IPSG for static hosts to work. If you only configure this command on a port without enabling
IP device tracking globally or by setting an IP device tracking maximum on that interface, IPSG with
static hosts rejects all the IP traffic from that interface
Beginning in privileged EXEC mode:
Command
Step 1
configure terminal
Step 2
ip device tracking
Step 3
interface interface-id
Step 4
switchport mode access
Step 5
switchport access vlan vlan-id
Step 6
ip verify source tracking port-security
Step 7
ip device tracking maximum number
OL-19720-02
Configuring IP Source Guard for Static Hosts on a Layer 2 Access Port, page 20-19
Purpose
Enter global configuration mode.
Turn on the IP host table, and globally enable IP device
tracking.
Enter interface configuration mode.
Configure a port as access.
Configure the VLAN for this port.
Enable IPSG for static hosts with MAC address filtering.
When you enable both IP source guard and port
Note
security by using the ip verify source
port-security interface configuration command:
The DHCP server must support option 82, or
the client is not assigned an IP address.
The MAC address in the DHCP packet is not
learned as a secure address. The MAC address
of the DHCP client is learned as a secure
address only when the switch receives
non-DHCP data traffic.
Establish a maximum limit for the number of static IPs
that the IP device tracking table allows on the port. The
range is 1to 10. The maximum number is 10.
Note
You must configure the ip device tracking
maximum limit-number interface configuration
command.
Catalyst 2975 Switch Software Configuration Guide
Configuring IP Source Guard
20-19

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents