Web-based Configuration Guide Security
110
7.6.3 Enabling Port IP Source Guard
Choose Local Device > Security > IP Source Guard > Basic Settings.
In Port List, click Edit in the Action column. Select Enabled and select the match rule, and click OK.
There are two match rules:
⚫ IP address: The source IP addresses of all IP packets passing through the port are checked. Packets are
allowed to pass through the port only when the source IP addresses of these packets match those in the
binding list.
⚫ IP address+ MAC address: The source IP addresses and MAC addresses of IP packets passing through the
port are checked. Packets are allowed to pass through the port only when both the L2 source MAC addresses
and L3 source IP addresses of these packets match an entry in the binding list.
Caution
● IP Source Guard is not supported to be enabled on a DHCP Snooping trusted port.
● Only on an L2 interface is IP Source Guard supported to be enabled.