18-16
Cisco ME 3400 EthernetAccess Switch SoftwareConfiguration Guide
78-17058-01
Chapter18 Configuring DHCP Features and IP Source Guard
Displaying IP Source Guard Information
To disable IP source guard with source IP address filtering, use the no ip verify source interface
configuration command.
To delete a static IP source binding entry, use the no ip source global configuration command.
This example shows how to enable IP source guard with source IP and MAC filtering on VLA Ns 10
and 11:
Switch# configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
Switch(config)# interface gigabitethernet1/0/1
Switch(config-if)# ip verify source port-security
Switch(config-if)# exit
Switch(config)# ip source binding 0100.0022.0010 vlan 10 10.0.0.2 interface
gigabitethernet1/0/1
Switch(config)# ip source binding 0100.0230.0002 vlan 11 10.0.0.4 interface
gigabitethernet1/0/1
Switch(config)# end
Displaying IP Source Guard Information
To display the IP source guard information, use one or more of the privileged EXEC co mm an ds in
Table18-3:
Step5 exit Return to global configuration mode.
Step6 ip source binding mac-address vlan
vlan-id ip-address inteface interface-id Add a static IP source binding.
Enter this command for each static binding.
Step7 end Return to privileged EXEC mode.
Step8 show ip verify source [interface
interface-id]Display the IP source guard configuration for all interfaces or for a
specific interface.
Step9 show ip source binding [ip-address]
[mac-address] [dhcp-snooping | static]
[inteface interface-id] [vlan vlan-id]
Display the IP source bindings on the switch, on a specific VLAN, or on
a specific interface.
Step10 copy running-config startup-config (Optional) Save your entries in the configuration file.
Command Purpose
Table18-3 Commands for Displaying IP Source Guard Information
Command Purpose
show ip source binding Display the IP source bindings on a switch.
show ip verify source Display the IP source guard configuration on the switch.