Enabling IP Source Guard on a Port or Range of Ports

IP Source Guard is disabled by default. You can enable IP Source Guard on DHCP snooping untrusted ports.
  1. Enter global configuration mode.
    device# configure terminal
  2. Enter interface configuration mode.
    device(config)# interface ethernet 1/1/1
  3. Enable IP Source Guard on the port.
    device(config-if-e10000-1/1/1)# source-guard enable
  4. To enable IP Source Guard on a range of ports, enter interface configuration mode and specify the range of ports.
    device(config-if-e10000-1/1/1)# interface ethernet 1/1/21 to 1/1/25
    When enabling IP Source Guard on a range of ports, you can choose only a range of ports within a given slot.
  5. Enable IP Source Guard on the range of ports specified in the previous step.
    device(config-mif-1/1/21-1/1/25)# source-guard enable
    Note: If you try to configure IP Source Guard across different modules, the following error message displays.
    device(config)# interface ethernet 2/1/10 to 12/1/10
    Error - cannot configure multi-ports on different slot