Huawei Quidway S9300 Configuration Manual page 107

Terabit routing switch v100r001c03
Table of Contents

Advertisement

Quidway S9300 Terabit Routing Switch
Configuration Guide - Security
Configuration Roadmap
Assume that the user is configured with an IP address statically. The configuration roadmap is
as follows:
1.
2.
3.
Data Preparation
To complete the configuration, you need the following data:
l
l
l
l
Procedure
Step 1 Enable the IP source guard function.
# Enable the IP source guard function on GE 1/0/1 connected to Host A.
[Quidway] interface gigabitethernet 1/0/1
[Quidway-GigabitEthernet1/0/1] ip source check user-bind enable
[Quidway-GigabitEthernet1/0/1] ip source check user-bind check-item ip-address mac-
address
[Quidway-GigabitEthernet1/0/1] quit
# Enable the IP source guard function on GE 1/0/2 connected to Host B.
[Quidway] interface gigabitethernet 1/0/2
[Quidway-GigabitEthernet1/0/2] ip source check user-bind enable
[Quidway-GigabitEthernet1/0/2] ip source check user-bind check-item ip-address mac-
address
[Quidway-GigabitEthernet1/0/2] quit
Step 2 Configure the check items of the static binding table.
# Configure Host A in the static binding table.
[Quidway] user-bind static ip-address 10.0.0.1 mac-address 0001-0001-0001
interface gigabitethernet 1/0/1 vlan 10
Step 3 Verify the configuration.
Run the display user-bind all command on the S9300 to view information about the binding
table.
<Quidway> display user-bind all
ifname
-------------------------------------------------------------------------------
GE1/0/1
-------------------------------------------------------------------------------
total count : 1
Issue 01 (2009-07-28)
Enable the IP source guard function on the interfaces connected to Host A and Host B.
Configure the check items of IP packets.
Configure a static binding table.
Interface connected to Host A: GE 1/0/1; interface connected to Host B: GE 1/0/2
Check items: IP address and MAC address
IP address of Host A: 10.0.0.1/24; MAC address of Host A: 1-1-1
VLAN where Host A resides: VLAN 10
NOTE
This configuration example provides only the commands related to the IP Source Guard configuration.
p/cvlan
0010/0000 S
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
tp lease
mac-address
0
0001-0001-0001 010.000.000.001
3 IP Source Guard Configuration
ip-address
vpn-instance
3-7

Advertisement

Table of Contents
loading

Table of Contents