CHAPTE R
27-1
Cisco IE 2000 Switch Software Configuration Guide
OL-25866-01
27
Configuring IP Source Guard
Finding Feature Information
Your software release may not support all the features documented in this chapter. For the latest feature
information and caveats, see the release notes for your platform and software release.
Use Cisco Feature Navigator to find information about platform support an d Cisco software image
support. To access Cisco Feature Navigator, go to http://www.cisco.com/go/cfn. An account on
Cisco.com is not required.

Prerequisites for IP Source Guard

You must globally configure the ip device tracking maximum limit-number interface configuration
command globally for IPSG for static hosts to work. If you only configure this command on a port
without enabling IP device tracking globally or setting an IP device tra cking maximum on that
interface, IPSG with static hosts will reject all the IP traffic from that interface. This requirement
also applies to IPSG with static hosts on a Layer 2 access port.

Restrictions for IP Source Guard

To use this feature, the switch must be running the LAN Base image.
IP source guard (IPSG) is supported only on Layer 2 ports, includi ng access and trunk ports.
Do not use IPSG for static hosts on uplink ports or trunk ports.

Information About IP Source Guard

IP Source Guard

IPSG is a security feature that restricts IP traffic on nonrouted, Layer 2 interfaces by filtering traffic
based on the DHCP snooping binding database and on manually configured IP source bindings. You can
use IPSG to prevent traffic attacks if a host tries to use the IP address of its neighbor.