D-Link DGS-3130 Emulator - Page 460
Interface, Filter-type, ip-mac, Filter-Mode, active, inactive-trust-port, inactive-no-snooping-vlan
View all D-Link DGS-3130 manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 460 highlights
DGS-3130 Layer 3 Stackable Managed Switch CLI Reference Guide Command Mode User/Privileged EXEC Mode. Any Configuration Mode. Command Default Level Level: 1. Usage Guideline Use this command to display the hardware port ACL entries for a port in the hardware table. It indicates the hardware filter behavior that IP source guard is verified upon. Example This example shows how to display when DHCP snooping is enabled on VLANs 100 to 110, the interface with IP source filter mode that is configured as IP, and that there is an existing IP address binding 10.1.1.1 on VLAN 100. Switch#show ip verify source interface ethernet 1/0/3 Interface --------eth1/0/3 eth1/0/3 Filter-type Filter-mode IP address MAC address VLAN ip active 10.1.1.1 - 100 ip active deny-all - 101-120 Total Entries: 2 Switch# This example shows how to display when the interface has an IP source filter mode that is configured as IP MAC and an existing IP MAC that binds IP address 10.1.1.10 to MAC address 00-01-01-01-01-01 on VLAN 100 and IP address 10.1.1.11 to MAC address 00-01-01-01-01-10 on VLAN 101. Switch# show ip verify source interface eth1/0/3 Interface --------eth1/0/3 eth1/0/3 eth1/0/3 Filter-type Filter-mode IP address MAC address VLAN ip-mac active 10.1.1.10 00-01-01-01-01-01 100 ip-mac active 10.1.1.11 00-01-01-01-01-10 101 ip-mac active deny-all - 102-120 Total Entries: 3 Switch# Display Parameters Interface Filter-type Filter-Mode The interface that has IP inspection enabled. The type of IP Source Guard in operation. ip: Only use an IP address to authorize IP packets. ip-mac: Use the IP and MAC address to authorize IP packets. active: Actively verify IP source entries. inactive-trust-port: Enable DHCP snooping to trust ports with no IP source entry verification active. inactive-no-snooping-vlan: No DHCP snooping VLAN configured with no IP source entry verification active. 456