D-Link DES-7200 Refrigerator User Manual


  Open as PDF
of 1968
 
DES-7200 Configuration Guide Chapter 11 IP Source Guard Configuration
11-4
hardware-based IP packet filtering database to pass through. In the latter case, IP
Source Guard checks the source IP addresses of IP packets.
11.1.3 Other Precautions of
Configuring IP Source
Guard
IP Source Guard is based on DHCP Snooping, namely port-based IP Source Guard
takes effect only on the untrusted port under the control of DHCP Snooping, not on
the trusted port or the interfaces in the VLAN not controlled by DHCP Snooping.
11.2 IP Source Guard
Configuration
11.2.1 Configuring IP Source
Guard on the Interface
By default, IP Source Guard is disabled on the interface and all the users connecting
to the interface can use the network. After enabling IP Source Guard on the interface,
it will filter the IP packets of the users connecting to the interface according to the
hardware-based IP packet filtering database.
Command Description
DES-7200(config)# interface
interface-id
Enter the interface configuration mode.
DES-7200(config)# [no] ip verify
source [port-security]
Enable IP Source Guard on the interface.
Use port-security to set MAC-based filtering.
The following example shows how to enable IP Source Guard on interface1:
DES-7200(config)# interface FastEthernet 0/1
DES-7200(config-if)# ip verify source
DES-7200(config-if)# end
Caution
The application of IP Source Guard is combined with DHCP Snooping.
That is to say, port-based IP Source Guard only takes effect on
untrusted port under the control of DHCP Snooping.