EasyManuals Logo

Cisco IE-5000 User Manual

Cisco IE-5000
1066 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #421 background imageLoading...
Page #421 background image
417
Cisco Systems, Inc. www.cisco.com
Configuring IP Source Guard
Prerequisites for IP Source Guard
You must globally configure the ip device tracking maximum limit-number interface configuration command
globally for IPSG for static hosts to work. If you only configure this command on a port without enabling IP device
tracking globally or setting an IP device tracking maximum on that interface, IPSG with static hosts will reject all the
IP traffic from that interface. This requirement also applies to IPSG with static hosts on a Layer 2 access port.
Restrictions for IP Source Guard
To use this feature, the switch must be running the LAN Base image.
IP source guard (IPSG) is supported only on Layer 2 ports, including access and trunk ports.
Do not use IPSG for static hosts on uplink ports or trunk ports.
Information About IP Source Guard
IP Source Guard
IPSG is a security feature that restricts IP traffic on nonrouted, Layer 2 interfaces by filtering traffic based on the DHCP
snooping binding database and on manually configured IP source bindings. You can use IPSG to prevent traffic attacks
if a host tries to use the IP address of its neighbor.
You can enable IPSG when DHCP snooping is enabled on an untrusted interface. After IPSG is enabled on an interface,
the switch blocks all IP traffic received on the interface except for DHCP packets allowed by DHCP snooping. A port
access control list (ACL) is applied to the interface. The port ACL allows only IP traffic with a source IP address in the IP
source binding table and denies all other traffic.
Note: The port ACL takes precedence over any router ACLs or VLAN maps that affect the same interface.
The IP source binding table bindings are learned by DHCP snooping or are manually configured (static IP source
bindings). An entry in this table has an IP address with its associated MAC address and VLAN number. The switch uses
the IP source binding table only when IPSG is enabled.
You can configure IPSG with source IP address filtering or with source IP and MAC address filtering.
Source IP Address Filtering
When IPSG is enabled with this option, IP traffic is filtered based on the source IP address. The switch forwards IP traffic
when the source IP address matches an entry in the DHCP snooping binding database or a binding in the IP source
binding table.
When a DHCP snooping binding or static IP source binding is added, changed, or deleted on an interface, the switch
modifies the port ACL by using the IP source binding changes and re-applies the port ACL to the interface.

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco IE-5000 and is the answer not in the manual?

Cisco IE-5000 Specifications

General IconGeneral
ModelIE-5000
CategoryIndustrial Ethernet Switch
Switching Capacity128 Gbps
Forwarding Rate95.2 Mpps
MAC Address Table Size16, 000 entries
Ports16 or 24 10/100/1000 ports
Uplink Ports4 SFP ports
Operating Temperature-40°C to 70°C
Power SupplyDual redundant power supplies
MountingDIN rail
ManagementWeb GUI, CLI, SNMP
Input Voltage24 VDC or 110/220 VAC
LayerLayer 2/3
Jumbo Frame SupportUp to 9216 bytes

Related product manuals