Configuring The Ipv4Sg Feature; Enabling Ipv4Sg On An Interface; Configuring A Static Ipv4Sg Binding - HP FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Configuring the IPv4SG feature

You cannot configure the IPv4SG feature on a service loopback interface. If IPv4SG is enabled on an
interface, you cannot assign the interface to a service loopback group.

Enabling IPv4SG on an interface

When you enable IPSG on an interface, the static and dynamic IPSG are both enabled.
Static IPv4SG uses static bindings configured by using the ip source binding command.
Dynamic IPv4SG generates dynamic bindings from related source modules. It uses the
bindings to filter incoming IPv4 packets based on the matching criteria specified in the ip verify
source command.
To implement dynamic IPv4SG, make sure the DHCP snooping or DHCP relay feature operates
correctly on the network.
To enable the IPv4SG feature on an interface:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Enable the IPv4SG
feature.

Configuring a static IPv4SG binding

You can configure global static and interface-specific static IPv4SG bindings.
Global static bindings take effect on all interfaces.
Interface-specific static bindings take priority over global static bindings. An interface first uses the
static bindings on the interface to match packets. If no match is found, the interface uses the global
bindings.
Configuring a global static IPv4SG binding
Step
1.
Enter system view.
2.
Configure a global static
IPv4SG binding.
Configuring a static IPv4SG binding on an interface
Step
1.
Enter system view.
Command
system-view
interface interface-type
interface-number
ip verify source
{ ip-address | ip-address
mac-address |
mac-address }
Command
system-view
ip source binding ip-address
ip-address mac-address
mac-address
Command
system-view
420
Remarks
N/A
The following interface types are
supported: Layer 2 Ethernet port, Layer 3
Ethernet interface, VLAN interface, and
Layer 3 aggregate interface.
By default, this IPv4SG feature is disabled
on an interface.
If you configure this command on an
interface multiple times, the most recent
configuration takes effect.
Remarks
N/A
No global static IPv4SG binding
exists.
Remarks
N/A

Advertisement

Table of Contents
loading

Table of Contents