This command sets the maximum number of entries that can be bound to
ip source-guard
an interface. Use the no form to restore the default setting.
max-binding
S
YNTAX
D
EFAULT
5
C
OMMAND
Interface Configuration (Ethernet)
C
OMMAND
◆
E
XAMPLE
This example sets the maximum number of allowed entries in the binding
table for port 5 to one entry.
Console(config)#interface ethernet 1/5
Console(config-if)#ip source-guard max-binding 1
Console(config-if)#
This command shows whether source guard is enabled or disabled on each
show ip source-
interface.
guard
C
OMMAND
Privileged Exec
E
XAMPLE
Console#show ip source-guard
Interface
---------
Eth 1/1
Eth 1/2
Eth 1/3
Eth 1/4
Eth 1/5
Eth 1/6
. .
.
ip source-guard max-binding number
no ip source-guard max-binding
number - The maximum number of IP addresses that can be
mapped to an interface in the binding table. (Range: 1-5)
S
ETTING
M
ODE
U
SAGE
This command sets the maximum number of address entries that can
be mapped to an interface in the binding table, including both dynamic
entries discovered by DHCP snooping and static entries set by the
source-guard
command.
M
ODE
Filter-type
Max-binding
-----------
-----------
DISABLED
DISABLED
DISABLED
DISABLED
SIP
DISABLED
– 931 –
| General Security Measures
C
27
HAPTER
5
5
5
5
1
5
IP Source Guard
ip