Enhancements

Release M.10.43 Enhancements

Enabling Dynamic IP Lockdown

To enable dynamic IP lockdown on all ports or specified ports, enter the ip source-lockdowncommand at the global configuration level. Use the no form of the command to disable dynamic IP lockdown.

Syntax: [no] ip source-lockdown [port-list]

Enables dynamic IP lockdown globally on all ports or on specified ports on the routing switch.

Operating Notes

Dynamic IP lockdown is enabled at the port configuration level and applies to all bridged or routed IP packets entering the switch. The only IP packets that are exempt from dynamic IP lockdown are broadcast DHCP request packets, which are handled by DHCP snooping.

DHCP snooping is a prerequisite for Dynamic IP Lockdown operation. The following restrictions apply:

DHCP snooping is required for dynamic IP lockdown to operate. To enable DHCP snooping, enter the DHCP-Snoopingcommand at the global configuration level.

Dynamic IP lockdown only filters packets in VLANs that are enabled for DHCP snooping. In order for Dynamic IP lockdown to work on a port, the port must be configured for at least one VLAN that is enabled for DHCP snooping.

To enable DHCP snooping on a VLAN, enter the dhcp-snooping vlan [vlan-id-range] command at the global configuration level or the dhcp-snoopingcommand at the VLAN configuration level.

Dynamic IP lockdown is not supported on a trusted port. (However, note that the DHCP server must be connected to a trusted port when DHCP snooping is enabled.)

By default, all ports are untrusted. To remove the trusted configuration from a port, enter the no dhcp-snooping trust <port-list> command at the global configuration level.

For more information on how to configure and use DHCP snooping, refer to the “Configuring Advanced Threat Protection” chapter in the Access Security Guide.

After you enter the ip source-lockdowncommand (enabled globally with the desired ports entered in <port-list>), the dynamic IP lockdown feature remains disabled on a port if any of the following conditions exist:

If DHCP snooping has not been globally enabled on the switch.

If the port is not a member of at least one VLAN that is enabled for DHCP snooping.

If the port is configured as a trusted port for DHCP snooping.

Dynamic IP lockdown is activated on the port only after you make the following configuration changes:

Enable DHCP snooping on the switch.

Configure the port as a member of a VLAN that has DHCP snooping enabled.

130

Page 140
Image 140
HP 3400CL-24G manual Operating Notes, Enabling Dynamic IP Lockdown