ip-source-guard
To enable source IP address filtering on a layer 2 port, use the ip-source-guard command in l2vpn bridge
group bridge domain configuration mode. To disable source IP address filtering, use the no form of this
command.
ip-source-guard logging
no ip-source-guard logging
Syntax Description
(Optional) Enables logging.logging
Command Default
IP Source Guard is disabled.
Command Modes
l2vpn bridge group bridge domain configuration
Command History
ModificationRelease
This command was introduced.Release 4.0.1
Usage Guidelines
To use this command, you must be in a user group associated with a task group that includes appropriate task
IDs. If the user group assignment is preventing you from using a command, contact your AAA administrator
for assistance.
Task ID
OperationsTask ID
read, writel2vpn
Examples
This example shows how to enable ip source guard on bridge bar:
RP/0/RSP0/CPU0:router# configure
RP/0/RSP0/CPU0:router(config)# l2vpn
RP/0/RSP0/CPU0:router(config-l2vpn)# bridge group b1
RP/0/RSP0/CPU0:router(config-l2vpn-bg)# bridge-domain bar
RP/0/RSP0/CPU0:router(config-l2vpn-bg-bd)# ip-source-guard
RP/0/RSP0/CPU0:router(config-l2vpn-bg-bd-ipsg)#
This example shows how to enable ip source guard logging on bridge bar:
RP/0/RSP0/CPU0:router# configure
RP/0/RSP0/CPU0:router(config)# l2vpn
RP/0/RSP0/CPU0:router(config-l2vpn)# bridge group b1
Cisco ASR 9000 Series Aggregation Services Router VPN and Ethernet Services Command Reference, Release
6.1.x
90
Point to Point Layer 2 Services Commands
ip-source-guard