IP S
OURCE
G
UARD
C
OMMANDS
23-13
found in the binding table and the entry type is static IP so urce guard
binding, the packet will be forwarded.
- If the DHCP snooping is enabled, IP source guard will check the
VLAN ID, source IP address, port number, and source MAC
address (for the sip-mac option). If a matching entry is found in the
binding table and the entry type is static IP source guard binding,
static DHCP snooping binding or dynamic DHCP snooping
binding, the packet will be forwarded.
- If IP source guard if enabled on an interface for which IP source
bindings (dynamically learned via DHCP snooping or manually
configured) are not yet configured, the switch will drop all IP traffic
on that port, except for DHCP packets.
Example
This example enables IP source guard on port 5.
Related Commands
ip source-guard binding (23-14)
ip dhcp snooping (23-18)
ip dhcp snooping vlan (23-20)
Console(config)#interface ethernet 1/5
Console(config-if)#ip source-guard sip
Console(config-if)#