Users Guide

Snooping and Inspecting Traffic 1043
Configuring IPSG
This example builds on the previous example and uses the same topology
shown in Figure 27-25. In this configuration example, IP source guard is
enabled on ports 1-20. DHCP snooping must also be enabled on these ports.
Additionally, because the ports use IP source guard with source IP and MAC
address filtering, port security must be enabled on the ports as well.
To configure the switch:
1
Enter interface configuration mode for the host ports and enable IPSG.
console(config)#interface range gi1/0/1-20
console(config-if)#ip verify source port-security
2
View IPSG information.
console(config-if)#show ip verify source
--More-- or (q)uit
Interface Filter Type IP Address MAC Address VLAN
--------- ----------- ------------ ----------------- ----
Gi1/0/1 ip-mac 192.168.3.45 00:1C:23:55:D4:8E 100
Gi1/0/2 ip-mac 192.168.3.40 00:1C:23:12:44:B6 100
Gi1/0/3 ip-mac 192.168.3.33 00:1C:23:AA:B8:01 100
Gi1/0/4 ip-mac 192.168.3.18 00:1C:23:67:D3:CC 100
Gi1/0/5 ip-mac 192.168.3.49 00:1C:23:55:1B:6E 100