Enabling IP Source Guard per-port-per-VLAN
This section is to be removed for 08.0.95
IP Source Guard can be enabled on a per-port-per-VLAN basis.
- Enter the global configuration mode by issuing the
configure terminalcommand. - Configure the port-based VLAN.
- Add ports Ethernet 5 through 8 as untagged ports.
- Add ports Ethernet 23 through Ethernet 24 as tagged ports and exit the mode.
- Enter interface configuration mode for port 23.
- Enable IP Source Guard on port Ethernet 23, a member of VLAN 12.
The following example configures IP Source Guard on a per-port-per-vlan.
device# configure terminal device(config)# vlan 12 device(config-vlan-12)# untag ethernet 5 to 8 device(config-vlan-12)# tag ethernet 23 to 24 device(config-vlan-12)# exit device(config)# interface ethernet 23 device(config-if-e1000-23)# per-vlan vlan12 device(config-if-e1000-23-vlan-12)# source-guard enable