912 Snooping and Inspecting Traffic
Configuring IPSG
This example builds on the previous example and uses the same topology
shown in Figure27-25. In this configuration example, IP source guard is
enabled on ports 1-20. DHCP snooping must also be enabled on these ports.
Additionally, because the ports use IP source guard with source IP and MAC
address filtering, port security must be enabled on the ports as well.
To configure the switch:
1
Enter interface configuration mode for the host ports and enable IPSG.
console(config)#interface range gi1/0/1-20
console(config-if)#ip verify source port-security
2
Enable port security on the ports.
console(config-if)#port security
3
View IPSG information.
console#show ip verify source
--More-- or (q)uit
Interface Filter IP Address MAC Address Vlan
--------- ------- ----------
Gi1/0/1 ip-mac 192.168.3.45 00:1C:23:55:D4:8E 100
Gi1/0/2 ip-mac 192.168.3.40 00:1C:23:12:44:B6 100
Gi1/0/3 ip-mac 192.168.3.33 00:1C:23:AA:B8:01 100
Gi1/0/4 ip-mac 192.168.3.18 00:1C:23:67:D3:CC 100
Gi1/0/5 ip-mac 192.168.3.49 00:1C:23:55:1B:6E 100