Chapter17
SecurityConfiguration
TableofContents
IPSourceGuard..............................................................171
ControlPlaneSecurityConguration..................................174
DAIConguration............................................................177
MFFConguration............................................................180
IPSourceGuard
IPSourceGuardOverview
IPSourceGuardisanapplicationbasedonDHCPSNOOPING.It
recordsdynamicuserinformation(IP ,MAC)byconstructingDHCP
SNOOPINGbindingdatabase.Afterenablingthisfunction,user
onlycanusetheaddressthatDHCPserverdynamicallydistributes
toaccessexternalnetwork.Thispreventsotherusersfromusing
otherIPaddressfordeceit.
ConfiguringIPSourceGuard
TocongureIPSourceGuardordeleteIPSourceGuard,usethe
followingcommands.
Step
CommandFunction
1
ZXR10(config-if-vlanX)#ipdhcpsnooping
ip-source-guard{ip-base|mac-base|
mac-ip-base}[vlan{default|<vlan-id>}]
ThisconguresIPSource
Guardofinterface.
2
ZXR10(config-if-vlanX)#noipdhcpsnooping
ip-source-guard
ThisdeletesIPSourceGuard
ofinterface.
CondentialandProprietaryInformationofZTECORPORATION171