DETAILED STEPS
PurposeCommand or Action
Enters global configuration mode.configure terminal
Example:
Step 1
switch# configure terminal
switch(config)#
Enters interface configuration mode for the specified
interface.
interface ethernet slot/port
Example:
Step 2
switch(config)# interface ethernet 2/3
switch(config-if)#
Enables IP Source Guard on the interface. The no form of
this command disables IP Source Guard on the interface.
[no] ip verify source dhcp-snooping-vlan
Example:
Step 3
switch(config-if)# ip verify source dhcp-snooping
vlan
Displays the running configuration for DHCP snooping,
including the IP Source Guard configuration.
(Optional) show running-config dhcp
Example:
Step 4
switch(config-if)# show running-config dhcp
Copies the running configuration to the startup
configuration.
(Optional) copy running-config startup-config
Example:
Step 5
switch(config-if)# copy running-config
startup-config
Adding or Removing a Static IP Source Entry
You can add or remove a static IP source entry on the device. By default, there are no static IP source entries.
SUMMARY STEPS
1. configure terminal
2. [no] ip source binding ip-address mac-address vlan vlan-id interface interface-type slot/port
3. (Optional) show ip dhcp snooping binding [interface interface-type slot/port]
4. (Optional) copy running-config startup-config
DETAILED STEPS
PurposeCommand or Action
Enters global configuration mode.configure terminal
Example:
Step 1
switch# configure terminal
switch(config)#
Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 9.x
408
Configuring IP Source Guard
Adding or Removing a Static IP Source Entry