Configuring Ip Source Guard (Cli Procedure) - Juniper JUNOS OS 10.4 - FOR EX REV 1 Manual

For ex series ethernet switches
Table of Contents

Advertisement

Configuring IP Source Guard (CLI Procedure)

Copyright © 2010, Juniper Networks, Inc.
You can use the IP source guard access port security feature on EX Series switches to
mitigate the effects of source IP address spoofing and source MAC address spoofing. If
IP source guard determines that a host connected to an access interface has sent a
packet with an invalid source IP address or source MAC address in the packet header, it
ensures that the switch does not forward the packet—that is, the packet is discarded.
You enable the IP source guard feature on VLANs. You can enable it on a specific VLAN,
on all VLANs, or on a VLAN range.
NOTE: IP source guard applies only to access interfaces and only to untrusted
interfaces. If you enable IP source guard on a VLAN that includes trunk
interfaces or an interface set to dhcp-trusted, the CLI shows an error when
you try to commit the configuration.
Before you configure IP source guard, be sure that you have:
Enabled DHCP snooping on the VLAN or VLANs on which you will configure IP source
guard. See "Enabling DHCP Snooping (CLI Procedure)" on page 3134.
Chapter 101: Configuring Port Security
3147

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junos os 10.4

Table of Contents