HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 172

Configuring a static IPv4 source guard binding entry on an interface

Page 172 highlights

All the fields in a static IPv4 binding entry are used by IP source guard to filter packets. For information about how to configure a static IPv4 binding entry, see "Configuring a static IPv4 source guard binding entry on an interface." Dynamic IPv4 binding entries can contain such information as the MAC address, IPv4 address, VLAN tag, ingress interface information, and entry type (such as DHCP snooping and DHCP relay). Which information in an entry is used by IP source guard to filter IPv4 packets is determined by the IPv4 source guard configuration on the interface: • If you bind both the source IP address and the source MAC address on the interface, the interface forwards a received packet only when the packet's source IP address and source MAC address both match a dynamic binding entry. If no match is found, the packet is dropped. • If you bind only the source IP address on the interface, the interface forwards a packet as long as the packet's source IP address matches a dynamic binding entry. If no match is found, the packet is dropped. To implement dynamic IPv4 source guard, make sure the DHCP snooping or DHCP relay function operate correctly on the network. To enable the IPv4 source guard function on an interface: Step 1. Enter system view. 2. Enter interface view. Command system-view interface interface-type interface-number Remarks N/A These types of interfaces are supported: Ethernet port and VLAN interface. 3. Enable the IPv4 source guard ip verify source ip-address function. [ mac-address ] By default, the function is disabled on an interface. Configuring a static IPv4 source guard binding entry on an interface Step 1. Enter system view. 2. Enter interface view. Command system-view interface interface-type interface-number 3. Configure a static IPv4 ip source binding ip-address binding entry. ip-address [ mac-address mac-address ] [ vlan vlan-id ] Remarks N/A These types of interfaces are supported: Ethernet interface and VLAN interface. By default, no static IPv4 binding entry is configured on an interface. The vlan vlan-id option is supported in only Ethernet interface view. 163

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

163
All the fields in a static IPv4 binding entry are used by IP source guard to filter packets. For information
about how to configure a static IPv4 binding entry, see "
Configuring a static IPv4 source guard binding
entry on an interface
."
Dynamic IPv4 binding entries can contain such information as the MAC address, IPv4 address, VLAN
tag, ingress interface information, and entry type (such as DHCP snooping and DHCP relay). Which
information in an entry is used by IP source guard to filter IPv4 packets is determined by the IPv4 source
guard configuration on the interface:
If you bind both the source IP address and the source MAC address on the interface, the interface
forwards a received packet only when the packet's source IP address and source MAC address
both match a dynamic binding entry. If no match is found, the packet is dropped.
If you bind only the source IP address on the interface, the interface forwards a packet as long as
the packet's source IP address matches a dynamic binding entry. If no match is found, the packet is
dropped.
To implement dynamic IPv4 source guard, make sure the DHCP snooping or DHCP relay function
operate correctly on the network.
To enable the IPv4 source guard function on an interface:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter interface view.
interface
interface-type
interface-number
These types of interfaces are
supported: Ethernet port and VLAN
interface.
3.
Enable the IPv4 source guard
function.
ip verify source ip-address
[
mac-address
]
By default, the function is disabled
on an interface.
Configuring a static IPv4 source guard binding entry on an
interface
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter interface view.
interface
interface-type
interface-number
These types of interfaces are supported:
Ethernet interface and VLAN interface.
3.
Configure a static IPv4
binding entry.
ip source binding ip-address
ip-address
[
mac-address
mac-address
] [
vlan
vlan-id
]
By default, no static IPv4 binding entry is
configured on an interface.
The
vlan
vlan-id
option is supported in only
Ethernet interface view.