Configuration Notes and Feature Limitations for IP Source Guard

The following configuration notes and feature limitations apply to IP Source Guard (IPSG):

  • Configuring IPSG static entries at the VLAN or port level is allowed only after IPSG is configured at the VLAN level, at the port level, or both.
  • IPSG configuration can be removed at the VLAN or port level only after all IPSG static entries are unconfigured at the VLAN or port level.
  • IPSG is supported on LAGs.
  • If you change the default VLAN ID when IPSG is enabled on a LAG, then IPSG is not inherited. All IPSG configuration is lost for the VLAN if the default VLAN ID is changed.
  • IPSG functions across reload.
  • RUCKUS ICX devices do not support IPSG and user ACLs on the same port.
  • RUCKUS devices do not support IPSG with ingress IPv4 ACLs for the same port, neither at VLAN-level, port-level, or across different levels. For ports with IPSG enabled, a special ingress IPv4 ACL viz SGACL has been introduced. Therefore, IPSG and SG ACL can be configured for the same port.
  • When IPSG is enabled for a LAG at the VLAN-level or VLAN-interface-level, IPSG entries learned on the LAG ports remain intact if the non-last member port of the LAG is removed. However, when the last member port is removed, it causes the LAG to undeploy. In that case, the IPSG entry is also flushed out.
  • IPSG is not supported for VLAN groups.
  • IPSG is not supported for VE interfaces.
  • When configuring IPSG on a range of ports, the configuration succeeds on all valid ports.
  • IPSG and IPv6 ACLs are supported for the same port.
  • IPSG can be enabled on tagged ports or untagged ports in a VLAN.
  • IPSG can be configured on a maximum of 511 VLANs.
  • IPSG and ACLs are supported together on the same device, as long as they are not configured on the same port or VLAN. If IPSG is enabled for a port, VLAN, or interface level, ACLs cannot be applied to inbound traffic on the port for the VLAN or interface using the ip access-group command. When IPSG is configured for a port at the VLAN or interface level, an error will occur if you attempt to apply an ACL to inbound traffic. To bind an IPSG ACL to an interface for incoming traffic, use the ip sg-access-group command. Refer to the ip sg-access-group command in the RUCKUS FastIron Command Reference for more information.
  • If IPSG is configured for a specified port for a VLAN, it cannot be configured globally for the VLAN. Refer to the RUCKUS FastIron Security Configuration Guide for more information.
  • The recommended number of entries for RUCKUS ICX devices is outlined in the following table.

    Recommended Number of Entries for RUCKUS ICX Devices

    Devices Recommended Maximum Number of IPSG Entries Per Device
    Re-added ICX 7150 values. Please confirm
    RUCKUS ICX 7150
    512
    RUCKUS ICX 7550 2048
    RUCKUS ICX 7650 4096
    RUCKUS ICX 7850 1526
    RUCKUS ICX 8100 1024
    RUCKUS ICX 8200 1024

    The recommended maximum number of IPSG entries for the stacking system for RUCKUS ICX 7650, ICX 7850, and ICX 8200 devices is 8192.

  • You can enable IPSG on a range of ports within a given slot only. Enabling IPSG across multiple slots is not supported.
  • If you enable IPSG in a network topology that has DHCP clients, you must also enable DHCP snooping. If you do not enable DHCP snooping, all IP traffic, including DHCP packets, is blocked.
  • If you enable IPSG in a network topology that does not have DHCP clients, you must create an IP source binding for each client that is allowed access to the network. Data packets are blocked if you do not create an IP source binding for each client.
  • IPSG protection enables concurrent support with MAC authentication.