UMN:CLI
User Manual
V5824G
304
To enable IP source guard with a source IP address and MAC address filtering on a port,
use the following command.
Command
Mode
Description
ip dhcp verify source port-
security
PORTS
Global
Enables IP source guard with a source IP address and
MAC address filtering on a port.
no ip dhcp verify source port-
security
PORTS
Disables IP source guard.
Note that the IP source guard is only enabled on DHCP snooping untrusted Layer 2 port!
If you try to enable this function on a trusted port, the error message will be shown up.
You cannot configure IP source guard with the
ip dhcp verify source
and
ip dhcp verify
source port-security
commands together.
8.5.8.2
Static IP Source Binding
The IP source binding table has bindings that are learned by DHCP snooping or manually
specified with the
ip dhcp verify source binding
command. The switch uses the IP
source binding table only when IP source guard is enabled.
To specify a static IP source binding entry, use the following command.
Command
Mode
Description
ip dhcp verify source binding
<1-4094>
PORT
A.B.C.D
MAC-
ADDR
Global
Specifies a static IP source binding entry.
1-4094: VLAN ID
PORT: port number
A.B.C.D: IP address
MAC-ADDR: MAC address
no ip dhcp verify source binding
{
A.B.C.D
|
all
}
Deletes a specified static IP source binding.
8.5.8.3
Displaying IP Source Guard Configuration
To display IP source binding table, use the following command.
Command
Mode
Description
show ip dhcp verify source
binding
Enable
Global
Shows IP source binding entries.
!
!