Show Ip Verify Source - Cisco Catalyst 4500 Series Command Reference Manual

Cisco ios command reference release ios xe 3.4.0sg and ios 15.1(2)sg
Hide thumbs Also See for Catalyst 4500 Series:
Table of Contents

Advertisement

Chapter 2
Cisco IOS Commands for the Catalyst 4500 Series Switches

show ip verify source

To display the IP source guard configuration and filters on a particular interface, use the show ip verify
source command.
Syntax Description
interface interface_num
Defaults
This command has no default settings.
Command Modes
Privileged EXEC mode
Command History
Release
12.1(19)EW
Examples
These examples show how to display the IP source guard configuration and filters on a particular
interface with the show ip verify source interface command:
Note
OL-27596 -01
show ip verify source [interface interface_num]
(Optional) Specifies an interface.
Modification
Support for this command was introduced on the Catalyst 4500 series switch.
This output appears when DHCP snooping is enabled on VLANs 10–20, interface fa6/1 has IP
source filter mode that is configured as IP, and an existing IP address binding 10.0.0.1 is on
VLAN 10:
Interface
Filter-type
---------
-----------
fa6/1
ip
fa6/1
ip
The second entry shows that a default PVACL (deny all IP traffic) is installed on the port for
those snooping-enabled VLANs that do not have a valid IP source binding.
This output appears when you enter the show ip verify source interface fa6/2 command and DHCP
snooping is enabled on VLANs 10–20, interface fa6/1 has IP source filter mode that is configured
as IP, and there is an existing IP address binding 10.0.0.1 on VLAN 10:
Interface
Filter-type
---------
-----------
fa6/2
ip
This output appears when you enter the show ip verify source interface fa6/3 command and the
interface fa6/3 does not have a VLAN enabled for DHCP snooping:
Interface
Filter-type
---------
-----------
fa6/3
ip
Catalyst 4500 Series Switch Cisco IOS Command Reference—Release IOS XE 3.4.0SG and IOS 15.1(2)SG)
Filter-mode
IP-address
-----------
---------------
active
10.0.0.1
active
deny-all
Filter-mode
IP-address
-----------
---------------
inactive-trust-port
Filter-mode
IP-address
-----------
---------------
inactive-no-snooping-vlan
show ip verify source
Mac-address
Vlan
--------------
---------
10
11-20
Mac-address
Vlan
--------------
---------
Mac-address
Vlan
--------------
---------
2-769

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents