Enabling IPv4SG on an interface
When you enable IPSG on an interface, the static and dynamic IPSG are both enabled.
Static IPv4SG uses static bindings configured by using the ip source binding command.
Dynamic IPv4SG generates dynamic bindings from related source modules. IPv4SG uses the bindings to filter incoming IPv4 packets based on the matching criteria specified in the ip verify source command.
To implement dynamic IPv4SG, make sure ARP snooping, DHCP snooping, DHCP relay agent, or DHCP server operates correctly on the network.
To enable the IPv4SG feature on an interface:
Step | Command | Remarks |
---|---|---|
1. Enter system view. | system-view | N/A |
2. Enter interface view. | interface interface-type interface-number | The following interface types are supported:
|
3. Enable the IPv4SG feature. | ip verify source { ip-address | ip-address mac-address | mac-address } | By default, the IPv4SG feature is disabled on an interface. If you configure this command on an interface multiple times, the most recent configuration takes effect. |