How to Configure IP Source Guard
Enabling IP Source Guard
SUMMARY STEPS
1.
configure terminal
2.
interface interface-id
3.
ip verify source [mac-check ]
4.
exit
5.
ip source binding mac-address vlan vlan-id ip-address interface interface-id
6.
end
DETAILED STEPS
PurposeCommand or Action
Enters the global configuration mode.configure terminal
Example:
Switch# configure terminal
Step 1
Specifies the interface to be configured, and enters
interface configuration mode.
interface interface-id
Example:
Switch(config)# interface gigabitethernet 1/0/1
Step 2
Enables IP source guard with source IP address filtering.ip verify source [mac-check ]
Step 3
Example:
Switch(config-if)# ip verify source
(Optional) mac-check—Enables IP Source Guard with
source IP address and MAC address filtering.
Returns to global configuration mode.exit
Example:
Switch(config-if)# exit
Step 4
Adds a static IP source binding.
ip source binding mac-address vlan vlan-id ip-address
interface interface-id
Step 5
Enter this command for each static binding.
Example:
Switch(config)# ip source binding 0100.0230.0002
vlan 11 10.0.0.4 interface gigabitethernet1/0/1
Catalyst 2960-XR Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX1
188 OL-29434-01
Configuring IP Source Guard
How to Configure IP Source Guard