Access Interface Connectivity
Configure Access Interface Connectivity
59
Best Practice User Guide for the Catalyst 3850 and Catalyst 3650 Switch Series
Use the show ip verify source command to confirm that the IP source guard is configured and working.
Use the show port-security command to confirm that access interfaces are configured for port security.
Use the show ip arp inspection interfaces command to confirm the rate and untrusted state of access
interfaces.
Use the show ipv6 nd raguard policy command to confirm that access interfaces are configured for
Router Advertisement Guard with specific policies.
show ip verify source
Interface Filter-type Filter-mode IP-address Mac-address Vlan
--------- ----------- ----------- --------------- ----------------- ----
Gi1/0/1 ip active deny-all 10-11
Gi1/0/2 ip active deny-all 10
Gi1/0/3 ip active deny-all 12
Gi1/0/4 ip active deny-all 10
show port-security
Secure Port MaxSecureAddr CurrentAddr SecurityViolation Security Action
(Count) (Count) (Count)
---------------------------------------------------------------------------
Gi1/0/1 11 1 0 Restrict
Gi1/0/2 11 1 0 Restrict
Gi1/0/3 11 1 0 Restrict
Gi1/0/4 11 1 0 Restrict
---------------------------------------------------------------------------
Total Addresses in System (excluding one mac per port) : 0
Max Addresses limit in System (excluding one mac per port) : 4096
show ip arp inspection interfaces
Interface Trust State Rate (pps) Burst Interval
--------------- ----------- ---------- --------------
Gi1/0/1 Untrusted 100 1
Gi1/0/2 Untrusted 100 1
Gi1/0/3 Untrusted 100 1
Gi1/0/4 Untrusted 100 1
show ipv6 nd raguard policy endhost_ipv6_raguard
Policy endhost_ipv6_raguard configuration:
device-role host
Policy endhost_ipv6_raguard is applied on the following targets:
Target Type Policy Feature Target range
Gi1/0/1 PORT endhost_ipv6_raguard RA guard vlan all
Gi1/0/2 PORT endhost_ipv6_raguard RA guard vlan all
Gi1/0/3 PORT endhost_ipv6_raguard RA guard vlan all
Gi1/0/4 PORT endhost_ipv6_raguard RA guard vlan all