Cisco Catalyst 2960-XR Security Configuration Manual page 213

Ios release 15.0 2 ex1
Hide thumbs Also See for Catalyst 2960-XR:
Table of Contents

Advertisement

Configuring IP Source Guard
Command or Action
Step 8
end
Example:
Switch(config)# end
Eight Examples
This example shows how to stop IPSG with static hosts on an interface.
Switch(config-if)# no ip verify source
Switch(config-if)# no ip device tracking max
This example shows how to enable IPSG with static hosts on a port.
Switch(config)# ip device tracking
Switch(config-if)# ip device tracking maximum 10
Switch(config-if)# ip verify source tracking
This example shows how to enable IPSG for static hosts with IP filters on a Layer 2 access port and to verify
the valid IP bindings on the interface Gi1/0/3:
Switch# configure terminal
Enter configuration commands, one per line.
Switch(config)# ip device tracking
Switch(config)# interface gigabitethernet1/0/3
Switch(config-if)# switchport mode access
Switch(config-if)# switchport access vlan 10
Switch(config-if)# ip device tracking maximum 5
Switch(config-if)# ip verify source tracking
Switch(config-if)# end
Switch# show ip verify source
Interface
---------
Gi1/0/3
Gi1/0/3
Gi1/0/3
This example shows how to enable IPSG for static hosts with IP-MAC filters on a Layer 2 access port, to
verify the valid IP-MAC bindings on the interface Gi1/0/3, and to verify that the number of bindings on this
interface has reached the maximum:
Switch# configure terminal
Enter configuration commands, one per line.
Switch(config)# ip device tracking
Switch(config)# interface gigabitethernet1/0/3
Switch(config-if)# switchport mode access
Switch(config-if)# switchport access vlan 1
Switch(config-if)# ip device tracking maximum 5
Switch(config-if)# ip verify source tracking
Switch(config-if)# end
Switch# show ip verify source
Interface
OL-29434-01
Filter-type
Filter-mode
-----------
-----------
ip trk
active
ip trk
active
ip trk
active
Filter-type
Filter-mode
Catalyst 2960-XR Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX1
Configuring IP Source Guard for Static Hosts on a Layer 2 Access Port
Purpose
Returns to privileged EXEC mode.
End with CNTL/Z.
IP-address
Mac-address
---------------
-----------------
40.1.1.24
40.1.1.20
40.1.1.21
End with CNTL/Z.
IP-address
Mac-address
Vlan
----
10
10
10
Vlan
191

Advertisement

Table of Contents
loading

Table of Contents