Enabling IP Source Guard on a VE
Removing this entire section. Please confirm
IP Source Guard can be enabled on a virtual interface.
-
- Enter global configuration mode by issuing the
configure terminalcommand. - Configure the port-based VLAN.
- Add port Ethernet 1 to VLAN 2.
- Create a VE on the VLAN.
- Enter the Virtual Interface mode.
- Enable IP Source Guard on Ethernet 2/1/36.
The following example configures IP Source Guard on a virtual interface.
device# configure terminal device(config)# vlan 2 device(config-vlan-2)# tagged ethe 2/1/36 ethe 12/1/38 to 12/1/39 ethe 17/2/2 ethe 55/1/32 device(config-vlan-2)# router-interface ve 2 device(config-vlan-2)# interface ve 2 device(config-vif-2)# source-guard enable ethernet 2/1/36
The following example configures IP Source Guard on untagged ports in a virtual interface.
device# configure terminal device(config)# vlan 2 device(config-vlan-2)# untagged ethe 1/2/3 ethe 2/1/11 ethe 3/1/5 to 3/1/6 ethe 20/1/5 to 20/1/6 ethe 20/2/3 device(config-vlan-2)# router-interface ve 2 device(config-vlan-2)# interface ve 2 device(config-vif-2)# source-guard enable e 20/2/3