TP-Link TL-SG5412F TL-SG5428 V1 CLI Reference Guide - Page 83

IP Source Guard Commands, ip source guard

Page 83 highlights

Chapter 14 IP Source Guard Commands IP Source Guard is to filter the IP packets based on the IP-MAC Binding entries. Only the packets matched to the IP-MAC Binding rules can be processed, which can enhance the bandwidth utility. ip source guard Description The ip source guard command is used to enable the IP Source Guard function for the specified port. To disable the IP Source Guard function, please use no ip source guard command. Syntax ip source guard {disable | sip | sip+mac} no ip source guard Parameter disable | sip | sip+mac--Security type. Disable indicates to disable the IP Source Guard feature for the port. Sip indicates that only the packets with its source IP address and port number matched to the IP-MAC binding rules can be processed. Sip_mac indicates that only the packets with its source IP address, source MAC address and port number matched to the IP-MAC binding rules can be processed. By default, the option is disabling. Command Mode Interface Configuration Mode(interface ethernet / interface range ethernet) Example Enable the IP Source Guard function for the ports 5-10. Configure that only the packets with its source IP address, source MAC address and port number matched to the IP-MAC binding rules can be processed: TP-LINK(config)# interface range ethernet 5-10 TP-LINK(config-if)# ip source guard sip+mac 71

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216

71
Chapter 14 IP Source Guard Commands
IP Source Guard is to filter the IP packets based on the IP-MAC Binding entries. Only the packets
matched to the IP-MAC Binding rules can be processed, which can enhance the bandwidth utility.
ip source guard
Description
The
ip source guard
command is used to enable the IP Source Guard function
for the specified port. To disable the IP Source Guard function, please use
no ip
source guard
command.
Syntax
ip source guard
{disable | sip | sip+mac}
no ip source guard
Parameter
disable | sip | sip+mac——Security type.
Disable indicates to disable the IP Source Guard feature for the port.
Sip indicates that only the packets with its source IP address and port number
matched to the IP-MAC binding rules can be processed.
Sip_mac indicates that only the packets with its source IP address, source MAC
address and port number matched to the IP-MAC binding rules can be
processed.
By default, the option is disabling.
Command Mode
Interface Configuration Mode
interface ethernet / interface range ethernet
Example
Enable the IP Source Guard function for the ports 5-10. Configure that only the
packets with its source IP address, source MAC address and port number
matched to the IP-MAC binding rules can be processed:
TP-LINK(config)# interface range ethernet
5-10
TP-LINK(config-if)# ip source guard
sip+mac