Verifying the dynamic IP lockdown configuration
To display the ports on which dynamic IP lockdown is configured, enter the
show ip
source-lockdown status
command at the global configuration level.
Syntax:
show ip source-lockdown status
Example 15 “The show ip source-lockdown status command output”
is an example of command
output. Note that the operational status of all switch ports is displayed, indicating whether or not
dynamic IP lockdown is supported on a port.
Example 15 The show ip source-lockdown status command output
HP Switch(config)# show ip source-lockdown status
Dynamic IP Lockdown Status Information
Global State : Disabled
Port Operational State
----- --------------------------
1 Active
2 Not in DHCP Snooping vlan
3 Disabled
4 Disabled
5 Trusted port, Not in DHCP Snooping vlan
.
.
.
Displaying the static configuration of IP-to-MAC bindings
To display the static configurations of IP-to-MAC bindings stored in the DHCP lease database, enter
the
show ip source-lockdown bindings
command.
Syntax:
show ip source-lockdown bindings
[
port-number
]
Task
Parameter
(Optional) Specifies the port number on which source IP-to-MAC address
and VLAN bindings are configured in the DHCP lease database.
port-number
Example 16 The show ip source-lockdown bindings command output
HP Switch(config)# show ip source-lockdown bindings
Dynamic IP Lockdown Bindings
Port IP Address Vlan Mac Address Not in HW
---- --------------- ---- ----------------- ---------
11 10.10.10.1 1111 001122-334455 YES
Trk1 10.10.10.2 2222 005544-332211 YES
In the
show ip source-lockdown bindings
command output, the “Not in HW” column
specifies whether or not (YES or NO) a statically configured IP-to-MAC and VLAN binding on a
specified port has been combined in the lease database maintained by the DHCP Snooping feature.
24
Updates for the HP Switch Software Access Security Guide