R21xx-HP FlexFabric 11900 Security Command Reference

155
Field Descri
p
tion
MAC Address
MAC address in the static IPv6 source guard binding entry. N/A means that
no MAC address is bound in the entry.
Interface Interface of the static IPv6 source guard binding entry.
VLAN
VLAN information in the static IPv6 source guard binding entry. N/A means
that the entry contains no VLAN information.
Type
Type of the static IPv6 source guard binding entry, where "static" indicates
manually configured entry.
Related commands
ipv6 source binding
ipv6 verify source
ip source binding
Use ip source binding to configure a static IPv4 source binding entry.
Use undo ip source binding to delete the static IPv4 source guard binding entries configured on the
interface.
Syntax
ip source binding ip-address ip-address [ mac-address mac-address ] [ vlan vlan-id ]
undo ip source binding ip-address ip-address [ mac-address mac-address ] [ vlan vlan-id ]
Default
No static IPv4 source binding entry is configured on an interface.
Views
Layer 2 Ethernet interface view, Layer 3 Ethernet interface view, VLAN interface view
Predefined user roles
network-admin
Parameters
ip-address ip-address: Specifies an IPv4 address for the static binding entry. The IPv4 address must be a
class A, B, or C address, and cannot be 127.x.x.x, 0.0.0.0, or a multicast IP address.
mac-address mac-address: Specifies a MAC address for the static binding entry. The MAC address must
be in H-H-H format, and cannot be all 0s, all Fs (a broadcast address), or a multicast address.
vlan vlan-id: Specifies a VLAN ID for the static binding entry. The value range for the vlan-id argument
is 1 to 4094. This option is only available in Layer 2 Ethernet interface view.
Usage guidelines
Static IPv4 source guard binding entries on an interface filter IPv4 packets received by the interface or
check user validity by cooperating with the ARP detection feature. A VLAN ID is required if the static IPv4
binding entry is used in the ARP detection function, and the specified VLAN must be enabled with the
ARP detection function. Otherwise, ARP packets cannot bypass the check of the static IPv4 binding entry.
All the fields except the VLAN in a static IPv4 binding entry are used by IP source guard to filter packets.