authentication source-guard-protection enable

Enables Source Guard Protection along with authentication on a specified interface.
Syntax
authentication source-guard-protection enable
no authentication source-guard-protection enable
Command Default

Source Guard Protection is not enabled.

Modes

Interface configuration mode

Usage Guidelines

When a new Flexible authentication session begins on a port that has Source Guard Protection enabled, the session either applies a dynamically created Source Guard ACL entry or it uses the dynamic IP ACL assigned by the RADIUS server. If a dynamic IP ACL is not assigned, the session uses the Source Guard ACL entry. The Source Guard ACL entry is permit ipsecure-ipany, where secure-ip is obtained from the ARP Inspection table or from the DHCP Secure table. The DHCP Secure table is comprised of DHCP Snooping and Static ARP Inspection entries. The Source Guard ACL permit entry is added to the hardware table after all of the following events occur:

  • The MAC address is authenticated
  • The IP address is learned
  • The MAC-to-IP mapping is checked against the Static ARP Inspection table or the DHCP Secure table

Note: In Flexible authentication, IP Source guard is applicable only for IPv4 traffic.

The Source Guard ACL entry is not written to the running configuration file. However, you can view the configuration using the show mac-authentication sessions command at the global level or for a specific interface.

Note: The secure MAC-to-IP mapping is assigned at the time of authentication and remains in effect as long as the session is active. The existing session doesn't get affected if the DHCP Secure table is updated after the session is authenticated and while the session is still active.

The Source Guard ACL permit entry is removed when the session expires or is cleared.

The no form of the command disables source guard protection.

Examples

The following example enables source guard protection on an interface.

device(config)# authentication
device(config-authen)# interface ethernet 1/1/1
device(config-if-e1000-1/1/1)# authentication source-guard-protection enable
History
Release version Command history
08.0.20 This command was introduced.
08.0.40a IP Source guard was supported for 802.1X authentication-enabled port.