2-405
Catalyst 3550 Multilayer Switch Command Reference
OL-8566-01
Chapter 2 Catalyst 3550 Switch Cisco IOS Commands
show ip verify source
show ip verify source
Use the show ip verify source user EXEC command to display the IP source guard configuration on the
switch or on a specific interface.
show ip verify source [interface interface-id] [ | {begin | exclude | include} expression]
Syntax Description
Command Modes User EXEC
Command History
Examples This is an example of output from the show ip verify source command:
Switch> show ip verify source
Interface Filter-type Filter-mode IP-address Mac-address Vlan
--------- ----------- ----------- --------------- -------------- ---------
Fa0/1 ip active 10.0.0.1 10
Fa0/1 ip active deny-all 11-20
Fa0/2 ip inactive-trust-port
Fa0/3 ip inactive-no-snooping-vlan
Fa0/4 ip-mac active 10.0.0.2 aaaa.bbbb.cccc 10
Fa0/4 ip-mac active 11.0.0.1 aaaa.bbbb.cccd 11
Fa0/4 ip-mac active deny-all deny-all 12-20
Fa0/5 ip-mac active 10.0.0.3 permit-all 10
Fa0/5 ip-mac active deny-all permit-all 11-20
In the previous example, this is the IP source guard configuration:
• On the Fast Ethernet 0/1 interface, Dynamic Host Configuration Protocol (DHCP) snooping is
enabled on VLANs 10 to 20. For VLAN
10, IP source guard with IP address filtering is configured
on the interface, and a binding exists on the interface. For VLANs 11 to 20, the second entry shows
that a default port access control list (ACL) is applied on the interface for the VLANs on which IP
source guard is not configured.
• The Fast Ethernet 0/2 interface is configured as trusted for DHCP snooping.
• On the Fast Ethernet 0/3 interface, DHCP snooping is not enabled on the VLANs to which the
interface belongs.
• On the Fast Ethernet 0/4 interface, IP source guard with source IP and MAC address filtering is
enabled, and static IP source bindings are configured on VLANs 10 and 11. For VLANs 12 to 20,
the default port ACL is applied on the interface for the VLANs on which IP source guard is not
configured.
interface interface-id (Optional) Display IP source guard configuration on a specific interface.
| begin (Optional) Display begins with the line that matches the expression.
| exclude (Optional) Display excludes lines that match the expression.
| include (Optional) Display includes lines that match the specified expression.
expression Expression in the output to use as a reference point.
Release Modification
12.2(25)SEA This command was introduced.