Figure 10-10 Configuring Ip Source Guard - Raisecom ISCOM2600G-HI (A) Series Configuration Manual

Table of Contents

Advertisement

Raisecom
ISCOM2600G-HI (A) Series Configuration Guide

Figure 10-10 Configuring IP Source Guard

Configuration steps
Step 1 Configure GE 1/1/1 to the trusted interface.
Raisecom#config
Raisecom(config)#interface gigaethernet 1/1/1
Raisecom(config-gigaethernet1/1/1)#ip verify source trust
Raisecom(config-gigaethernet1/1/1)#exit
Step 2 Configure static binding.
Raisecom(config)#ip verify source
Raisecom(config)#ip source binding 10.10.10.1 gigaethernet 1/1/2
Step 3 Enable global dynamic IP Source Guard binding.
Raisecom(config)#ip verify source dhcp-snooping
The Switch permits all IP packets on GE 1/1/1 to pass.
GE 1/1/2 permits those IP packets to pass, of which the IP address is 10.10.10.1, the
subnet mask is 255.255.255.0, and the status meets the dynamic binding learnt by DHCP
Snooping.
Other interfaces only permit the packets meeting DHCP Snooping learnt dynamic
binding to pass.
Raisecom Proprietary and Confidential
Copyright © Raisecom Technology Co., Ltd.
10 Security
443

Advertisement

Table of Contents
loading

Table of Contents

Save PDF