317
Ste
Command
Remarks
2. Enter interface view.
interface interface-type
interface-number
The following interface types are
supported:
• Layer 2 Ethernet port.
• Layer 3 Ethernet interface.
• Layer 3 Ethernet subinterface.
• VLAN interface.
• Layer 3 aggregate interface.
3. Enable the IPv4 source guard
function.
ip verify source { ip-address |
ip-address mac-address |
mac-address }
By default, the function is disabled
on an interface.
If you configure this command on
an interface multiple times, the
most recent configuration takes
effect.
Configuring a static IPv4 source guard binding entry
You can configure global and interface-specific static IPv4 source guard binding entries.
A global static binding entry defines both the source IP address and source MAC address of packets that
can be forwarded. It takes effect on all interfaces.
Interface-specific static binding entries take priority over global static binding entries. An interface first
compares an incoming packet with the static binding entries configured on the interface. If no match is
found, the interface uses the global entries.
Configuring a global static IPv4 source guard binding entry
Step Command Remarks
1. Enter system view.
system-view N/A
2. Configure a global
static IPv4 source
guard binding entry.
ip source binding ip-address ip-address
mac-address mac-address
No global static IPv4
source guard binding
entry exists.
Configuring a static IPv4 source guard binding entry on an interface
Ste
Command
Remarks
1. Enter system view.
system-view N/A
2. Enter interface view.
interface interface-type
interface-number
The following interface types are supported:
• Layer 2 Ethernet port.
• Layer 3 Ethernet interface.
• Layer 3 Ethernet subinterface.
• VLAN interface.