HP 6125G HP 6125G & 6125G/XG Blade Switches Security Command Reference - Page 257

ip verify source

Page 257 highlights

vlan vlan-id: Specifies the VLAN for the static binding. vlan-id is the ID of the VLAN to be bound, in the range of 1 to 4094. Description Use ip source binding to configure a static IPv4 source guard entry on a port. Use undo ip source binding to delete a static IPv4 source guard entry from a port. By default, no static IPv4 binding entry exists on a port. IP source guard does not use the VLAN information (if specified) in static IPv4 binding entries to filter packets. When the ARP detection function is configured, be sure to specify the VLAN where ARP detection is configured in static IPv4 binding entries. Otherwise, ARP packets are discarded because they cannot match any static IPv4 binding entry. For more information about the ARP detection function, see Security Configuration Guide. You cannot configure the same static binding entry repeatedly on one port, but you can configure the same static entry on different ports. You cannot configure a static binding entry on a port that is in an aggregation group or a service loopback group. Related commands: display ip source binding static. Examples # Configure a static IPv4 binding entry (IP+MAC binding) on port GigabitEthernet 1/0/1. system-view [Sysname] interface gigabitethernet 1/0/1 [Sysname-GigabitEthernet1/0/1] ip source binding ip-address 192.168.0.1 mac-address 0001-0001-0001 ip verify source Syntax ip verify source { ip-address | ip-address mac-address | mac-address } View undo ip verify source Layer 2 Ethernet interface view, VLAN interface view Default level 2: System level Parameters ip-address: Binds source IPv4 addresses to the port. ip-address mac-address: Binds source IPv4 addresses and MAC addresses to the port. mac-address: Binds source MAC addresses to the port. Description Use ip verify source to enable the IPv4 source guard function on a port and specify the elements to be included in the port's dynamic binding entries. Use undo ip verify source to restore the default. 248

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291

248
vlan
vlan-id
: Specifies the VLAN for the static binding.
vlan-id
is the ID of the VLAN to be bound, in the
range of 1 to 4094.
Description
Use
ip source binding
to configure a static IPv4 source guard entry on a port.
Use
undo ip source binding
to delete a static IPv4 source guard entry from a port.
By default, no static IPv4 binding entry exists on a port.
IP source guard does not use the VLAN information (if specified) in static IPv4 binding entries to filter
packets.
When the ARP detection function is configured, be sure to specify the VLAN where ARP detection is
configured in static IPv4 binding entries. Otherwise, ARP packets are discarded because they cannot
match any static IPv4 binding entry. For more information about the ARP detection function, see
Security
Configuration Guide
.
You cannot configure the same static binding entry repeatedly on one port, but you can configure the
same static entry on different ports.
You cannot configure a static binding entry on a port that is in an aggregation group or a service
loopback group.
Related commands:
display ip source binding static
.
Examples
# Configure a static IPv4 binding entry (IP+MAC binding) on port GigabitEthernet 1/0/1.
<Sysname> system-view
[Sysname] interface gigabitethernet 1/0/1
[Sysname-GigabitEthernet1/0/1] ip source binding ip-address 192.168.0.1 mac-address
0001-0001-0001
ip verify source
Syntax
ip verify source
{
ip-address
|
ip-address mac-address
|
mac-address
}
undo ip verify source
View
Layer 2 Ethernet interface view, VLAN interface view
Default level
2: System level
Parameters
ip-address
: Binds source IPv4 addresses to the port.
ip-address mac-address
: Binds source IPv4 addresses and MAC addresses to the port.
mac-address
: Binds source MAC addresses to the port.
Description
Use
ip verify source
to enable the IPv4 source guard function on a port and specify the elements to be
included in the port’s dynamic binding entries.
Use
undo ip verify source
to restore the default.