R211x-HP Flexfabric 11900 Security Configuration Guide
208
Ste
p
Command
Remarks
1. Enter system view.
system-view N/A
2. Enter interface view.
interface interface-type
interface-number
The interface-type argument can
be Layer 2 Ethernet interface,
Layer 3 Ethernet interface, and
VLAN interface.
3. Enable the IPv4 source guard
function.
ip verify source { ip-address |
ip-address mac-address |
mac-address }
By default, the function is disabled
on an interface.
If you configure this command on
an interface multiple times, the
most recent configuration takes
effect.
Configuring a static IPv4 source guard binding entry
Static IPv4 source guard binding entries include global static IPv4 source entries and interface-specific
static IPv4 source guard binding entries.
A global static IPv4 source guard binding entry defines both the source IP address and source MAC
address of packets that can be forwarded, and it takes effect on all interfaces.
Static IPv4 source guard binding entries on an interface take priority over the global static IPv4 source
guard binding entries. An interface first uses the static IPv4 source guard binding entries configured for
the interface to match a received packet. If no match is found, the interface uses the global entries to
match the packet.
Configuring a global static IPv4 source guard binding entry
Step Command Remarks
1. Enter system view.
system-view N/A
2. Configure a global
static IPv4 source
guard binding entry.
ip source binding ip-address ip-address
mac-address mac-address
No global static IPv4
source guard binding
entry exists.
Configuring a static IPv4 source guard binding entry on an interface
Ste
p
Command
Remarks
1. Enter system view.
system-view N/A
2. Enter interface view.
interface interface-type
interface-number
The interface-type argument can be Layer 2
Ethernet interface, Layer 3 Ethernet
interface, and VLAN interface.










