EasyManuals Logo

Cisco 500 Series Administration Guide

Cisco 500 Series
653 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #473 background imageLoading...
Page #473 background image
Security
IP Source Guard
471 Cisco 500 Series Stackable Managed Switch Administration Guide
21
• When the ports status changes from DHCP untrusted to DHCP trusted, the
static IP address filtering entries remain in the Binding database, but they
become inactive.
• Port security cannot be enabled if source IP and MAC address filtering is
configured on a port.
• IP Source Guard uses TCAM resources and requires a single TCAM rule per
IP Source Guard address entry. If the number of IP Source Guard entries
exceeds the number of available TCAM rules, the extra addresses are
inactive.
Filtering
If IP Source Guard is enabled on a port then:
• DHCP packets allowed by DHCP Snooping are permitted.
• If source IP address filtering is enabled:
- IPv4 traffic: Only traffic with a source IP address that is associated with
the port is permitted.
- Non IPv4 traffic: Permitted (Including ARP packets).
Configuring IP Source Guard Work Flow
To configure IP Source Guard:
STEP 1 Enable DHCP Snooping in the IP Configuration > DHCP > Properties page or in the
Security > DHCP Snooping > Properties page.
STEP 2 Define the VLANs on which DHCP Snooping is enabled in the IP Configuration >
DHCP > Interface Settings page.
STEP 3 Configure interfaces as trusted or untrusted in the IP Configuration > DHCP >
DHCP Snooping Interface page.
STEP 4 Enable IP Source Guard in the Security > IP Source Guard > Properties page.
STEP 5 Enable IP Source Guard on the untrusted interfaces as required in the Security > IP
Source Guard > Interface Settings page.
STEP 6 View entries to the Binding database in the Security > IP Source Guard > Binding
Database page.

Table of Contents

Other manuals for Cisco 500 Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco 500 Series and is the answer not in the manual?

Cisco 500 Series Specifications

General IconGeneral
ModelCisco 500 Series
CategorySwitch
MountingRack-mountable
ManagementWeb-based, CLI, SNMP
Ports24, 48
Port Speed10/100/1000 Mbps
PoE SupportAvailable on some models
Switching CapacityUp to 176 Gbps
MAC Address Table Size16, 000 entries
SecurityACLs, 802.1X
Quality of Service (QoS)Yes
DimensionsVaries by model
WeightVaries by model
Humidity10% to 90% non-condensing
Power SupplyInternal
Power ConsumptionVaries by model
Jumbo Frame SupportUp to 9216 bytes

Related product manuals