Enabling IP Source Guard on Multiple VLANs

You can enable IP Source Guard (IPSG) on a switch or a router for a range of ports in multiple VLANs or all ports on multiple VLANs. The following task configures IPSG on a single port on multiple VLANs.
Note: IPSG snooping can be configured on a maximum of 511 VLANs.
  1. Enter global configuration mode.
    device# configure terminal
  2. Configure the port-based VLANs.
    device(config)# vlan 100 to 150
  3. Add port Ethernet 1/1/12 as a tagged port.
    device(config-mvlan-100-150)# tagged ethernet 1/1/12
  4. Enable IPSG on the tagged port for multiple VLANs.
    device(config-mvlan-100-150)# source-guard enable ethernet 1/1/12

The following example configures IPSG on a range of ports on multiple VLANs.

device# configure terminal
device(config)# vlan 100 to 150
device(config-mvlan-100-150)# tagged ethernet 1/1/23 to 1/1/24
device(config-mvlan-100-150)# source-guard enable ethernet 1/1/23 to 1/1/24

The following example configures IPSG on a single port on multiple VLANs.

device# configure terminal
device(config)# vlan 151 to 200
device(config-mvlan-151-200)# tagged ethernet 1/1/23
device(config-mvlan-151-200)# source-guard enable ethernet 1/1/23

The following example configures IPSG on all ports on multiple VLANs.

device# configure terminal
device(config)# vlan 151 to 200
device(config-mvlan-151-200)# tagged ethernet 1/1/23 to 1/1/24
device(config-mvlan-151-200)# source-guard enable