Enabling IP Source Guard for a VLAN

You can enable IP Source Guard (IPSG) on a switch or a router for a range of ports in a VLAN or on the entire VLAN.
  1. Enter global configuration mode.
    device# configure terminal
  2. Configure the port-based VLAN.
    device(config)# vlan 12
  3. Add Ethernet ports 1/1/5 through 1/1/8 as untagged ports.
    device(config-vlan-12)# untagged ethernet 1/1/5 to 1/1/8
  4. Add Ethernet ports 1/1/23 through Ethernet 1/1/24 as tagged ports.
    device(config-vlan-12)# tagged ethernet 1/1/23 to 1/1/24
    
  5. Enable IPSG on the tagged ports.
    device(config-vlan-12)# source-guard enable ethernet 1/1/23 to 1/1/24

The following example configures IPSG on the specified tagged ports on the specified VLAN.

device# configure terminal
device(config)# vlan 12
device(config-vlan-12)# untagged ethernet 1/1/5 to 1/1/8
device(config-vlan-12)# tagged ethernet 1/1/23 to 1/1/24
device(config-vlan-12)# source-guard enable ethernet 1/1/23 to 1/1/24

The following example configures IPSG on a single tagged port on a VLAN.

device# configure terminal
device(config)# vlan 12
device(config-vlan-12)# untagged ethernet 1/1/5 to 1/1/8
device(config-vlan-12)# tagged ethernet 1/1/23 to 1/1/24
device(config-vlan-12)# source-guard enable ethernet 1/1/23

The following example configures IPSG on all ports (tagged and untagged) on a VLAN.

device# configure terminal
device(config)# vlan 12
device(config-vlan-12)# untagged ethernet 1/1/5 to 1/1/8
device(config-vlan-12)# tagged ethernet 1/1/23 to 1/1/24
device(config-vlan-12)# source-guard enable