Configuration Notes and Feature Limitations for IP Source Guard

The following configuration notes and feature limitations apply to IP Source Guard (IPSG):

  • Configuring IPSG static entries at the VLAN or port level is allowed only after IPSG is configured at the VLAN level, at the port level, or both.
  • IPSG configuration can be removed at the VLAN or port level only after all IPSG static entries are unconfigured at the VLAN or port level.
  • IPSG is supported on LAGs.
  • If you change the default VLAN ID when IPSG is enabled on a LAG, then IPSG is not inherited. All IPSG configuration is lost for the VLAN if the default VLAN ID is changed.
  • IPSG functions across reload.
  • RUCKUS ICX devices do not support IPSG and dynamic ACLs on the same port.
  • RUCKUS devices do not support IPSG with ingress IPv4 ACLs for the same port, neither at VLAN-level, port-level, or across different levels. For ports with IPSG enabled, a special ingress IPv4 ACL viz SGACL has been introduced. Therefore, IPSG and SG ACL can be configured for the same port.
  • When IPSG is enabled for a LAG at the VLAN-level or VLAG-interface-level, IPSG entries learned on the LAG ports remain intact if the non-last member port of lag is removed. However, when the last member port is removed, it causes the LAG to undeploy. In that case, the IPSG entry is also flushed out.
  • IPSG is not supported for VLAN groups. If upgrading from FastIron 08.0.92 to FastIron 08.0.95, IPSG is not configured for a VLAN group, even if this was previously configured.
  • IPSG is not supported for VE interfaces.
  • When configuring IPSG on a range of ports, the configuration succeeds on all valid ports.
  • IPSG and IPv6 ACLs are supported for the same port.
  • IP Source Guard cannot be enabled on a per-port-per-VLAN basis.
  • IPSG can be enabled on tagged ports or untagged ports in a VLAN.
  • IPSG snooping can be configured on a maximum of 511 VLANs.
  • For router images, IPSG cannot be configured in interface subtype configuration mode for tagged ports of a VLAN.
  • IPSG and ACLs are supported together on the same device, as long as they are not configured on the same port or VLAN. If IPSG is enabled for a port, VLAN, or interface level, ACLs cannot be applied to inbound traffic on the port for the VLAN or interface using the ip access-group command. When IPSG is configured for a port at the VLAN or interface level, an error will occur if you attempt to apply an ACL to inbound traffic. To bind an IPSG ACL to an interface for incoming traffic, use the ip sg-access-group command. Refer to the ip sg-access-group command in the RUCKUS FastIron Command Reference command for more information.
  • If IPSG is configured for a specified port for a VLAN, it cannot be configured globally for the VLAN. Beginning with FastIron 08.0.40a, IPSG can be enabled with Flexible Authentication using the authentication source-guard-protection enable command. Refer to the RUCKUS FastIron Security Configuration Guide for more information.
  • For ICX 7750 platforms, it is not possible to bind IPSG ACLs for interfaces or VLANs when IPSG ACLs are created with a TCP or UDP protocol filter that has the “neq” option on both the source and destination addresses.
  • Some RUCKUS devices with lesser TCAM (such as the ICX 7150) are limited to 256 IPSG entries. The scaling number of 256 entries per port in the ICX 7150 and 512 entries per port in the other platforms is not guaranteed and depends on the rules regarding free TCAM. The amount of free TCAM determines the number of allowed IPSG entries because IPSG is programmed in the TCAM and there are fewer TCAM rules.
  • The recommended number of entries for RUCKUS ICX devices is outlined in the following table:.

    Recommneded Number of Entries for Ruckus ICX Devices

    Devices Recommended Maximum Number of IPSG Entries Per Device
    RUCKUS ICX 7150 512
    RUCKUS ICX 7250 3072
    RUCKUS ICX 7450 2816
    RUCKUS ICX 7550 2048
    RUCKUS ICX 7650 4096
    RUCKUS ICX 7750 2048
    RUCKUS ICX 7850 1526

    The recommended maximum number of IPSG entries for the stacking system for RUCKUSICX 7250, ICX 7450, ICX 7750, ICX 7650, ICX 7750, and ICX 7850 devices is 8192.

  • When IPSG and DHCP snooping are enabled on SPX Virtual (PE) ports and DHCP clients are learned on the port, system performance may be degraded if more than 256 clients are learned on the same port. This is applicable for all platforms used as PE ports.
  • You can enable IPSG on a range of ports within a given slot only. Enabling IPSG across multiple slots is not supported.
  • If you enable IPSG in a network topology that has DHCP clients, you must also enable DHCP snooping. If you do not enable DHCP snooping, all IP traffic, including DHCP packets, is blocked.
  • If you enable IIPSG in a network topology that does not have DHCP clients, you must create an IP source binding for each client that is allowed access to the network. Data packets are blocked if you do not create an IP source binding for each client.
  • IPSG protection enables concurrent support with MAC authentication.
  • IPSG supports multi-VRF instances.
  • Rate-limiting based on source IP address cannot be combined with IPSG. Thus, a fixed rate-limit input cannot be configured when IPSG is enabled on the port.