Chapter17SecurityConguration
FIGURE37IPSOURCEGUARDCONFIGURATION
IPSourceGuardbasedonMACaddressisconguredonthe
gei_1/2interfacemode.AfergettingIPaddressdynamically,PC
canonlypassthedatapacketwithsourceMACaddressthatis
localhostNICcard.
CongurationofR1:
ZXR10(config)#ipdhcpsnoopingenable
ZXR10(config)#ipdhcpsnoopingvlan100
ZXR10(config)#ipdhcpsnoopingtrustgei_1/1
ZXR10(config)#interfacegei_1/2
ZXR10(config-if)#ipdhcpsnnopingip-source-guardmac-base
IPSourceGuardConfigurationbasedonIP
AddressandMACaddress
InFigure38,DHCPserverconnectsgei_1/1onR1,administra-
torsetsmanagementDHCP ,gei_1/1belongstovlan100.DHCP
SnoopingfunctionisenabledinVLAN100andinterfacegei_1/1is
conguredastrusted.PCconnectsgei_1/2ofswitch,whichbe-
longstovlan100.
FIGURE38IPSOURCEGUARDCONFIGURATION
IPSourceGuardbasedonMACaddressisconguredonthe
gei_1/2interfacemode.AftergettingIPaddressdynamically,PC
canonlypassthedatapacketwithsourceMACaddressthatis
localhostNICcardandsourceIPaddressthatisdistributedby
DHCPserver .
CongurationofR1:
ZXR10(config)#ipdhcpsnoopingenable
ZXR10(config)#ipdhcpsnoopingvlan100
ZXR10(config)#ipdhcpsnoopingtrustgei_1/1
ZXR10(config)#interfacegei_1/2
ZXR10(config-if)#ipdhcpsnnopingip-source-guardmac-ip-base
CondentialandProprietaryInformationofZTECORPORATION173