source-guard enable

Enables IP Source Guard (IPSG) on a port or a range of ports, per-port per-VLAN, or a VLAN or a range of VLANs.
Syntax
source-guard enable [ ethernet unit/slot/port to unit/slot/port | ethernet unit/slot/port ] [ lag lag-id to lag-id | lag lag-id ]...
no source-guard enable [ ethernet unit/slot/port to unit/slot/port | ethernet unit/slot/port ] [ lag lag-id to lag-id | lag lag-id ]...
Command Default

IPSG is disabled.

Parameters
ethernet unit/slot/port
Specifies the Ethernet interface and the interface ID in the unit/slot/port format.
to unit/slot/port
Specifies a range of Ethernet interfaces.
lag lag-id
Specifies the LAG virtual interface.
to lag-id
Specifies a range of LAG IDs.
Modes

Interface configuration mode

VLAN configuration mode

Usage Guidelines

You can enable IPSG on a range of ports within a given slot only. Enabling IPSG across multiple slots is not supported.

For Interface configuration mode, this command is supported only for Ethernet interfaces and VLAG interfaces.

If IPSG is configured for a specified port for a VLAN, it cannot be configured globally for the VLAN.

IPSG and ACLs are supported together on the same device, as long as they are not configured on the same port or VLAN. If IPSG is enabled for a port, at the VLAN or interface level, ACLs cannot be applied to inbound traffic on the port for the VLAN or interface using the ip access-group command. When IPSG is configured for a port at the VLAN or interface level, an error will occur if you attempt to apply an ACL to inbound traffic. To bind an IPSG ACL to an interface for incoming traffic, use the ip sg-access-group command. Refer to the ip sg-access-group command for more information.

The no form of the command disables IPSG on the specified interface.

Examples

The following example enables IPSG for interface Ethernet 1/1/4.

device# configure terminal
device(config)# interface ethernet 1/1/4
device(config-if-e10000-1/1/4)# source-guard enable

The following example enables IPSG on a range of ports in the same slot.

device# configure terminal
device(config)# interface ethernet 1/1/1
device(config-if-e10000-1/1/1)# interface ethernet 1/1/21 to 1/1/25
decice(config-mif-1/1/21-1/1/25)# source-guard enable

The following error message displays if you try to configure ports across multiple slots.

device(config)# interface ethernet 1/1/18 to 2/1/18
Error - cannot configure multi-ports on different slot

The following example configures IPSG on a range of ports on a VLAN.

device# configure terminal
device(config)# vlan 12
device(config-vlan-12)# untagged ethernet 1/1/5 to 1/1/8
device(config-vlan-12)# tagged ethernet 1/1/23 to 1/1/24
device(config-vlan-12)# source-guard enable ethernet 1/1/23 to 1/1/24

The following example configures IPSG on a single port on a VLAN.

device# configure terminal
device(config)# vlan 12
device(config-vlan-12)# untagged ethernet 1/1/5 to 1/1/8
device(config-vlan-12)# tagged ethernet 1/1/23 to 1/1/24
device(config-vlan-12)# source-guard enable ethernet 1/1/23

The following example configures IPSG on all ports on a VLAN.

device# configure terminal
device(config)# vlan 12
device(config-vlan-12)# untagged ethernet 1/1/5 to 1/1/8
device(config-vlan-12)# tagged ethernet 1/1/23 to 1/1/24
device(config-vlan-12)# source-guard enable

The following example configures IPSG on a range of ports on multiple VLANs.

device# configure terminal
device(config)# vlan 100 to 150
device(config-mvlan-100-150)# tagged ethernet 1/1/23 to 1/1/24
device(config-mvlan-100-150)# source-guard enable ethernet 1/1/23 to 1/1/24

The following example configures IPSG on all ports on multiple VLANs.

device# configure terminal
device(config)# vlan 151 to 200
device(config-mvlan-151-200)# tagged ethernet 1/1/23 to 1/1/24
device(config-mvlan-151-200)# source-guard enable

The following example configures IPSG for a LAG port for a VLAN.

device# configure terminal
device(config)# vlan 12
device(config-vlan-12)# tagged lag 9
device(config-vlan-12)# source-guard enable lag 9
History
Release version Command history
08.0.40a This command was modified to support enabling IPSG on a range of ports.
08.0.61 An example was added for configuring IP Source Guard on a VLAN.
08.0.80 Support was added for configuring this command on a range of VLANs.
08.0.95 This command was modified to remove support for VE interfaces and VLAN groups.