Enabling IP Source Guard on a VE

Removing this entire section. Please confirm
IP Source Guard can be enabled on a virtual interface.
  1. Enter global configuration mode by issuing the configure terminal command.
    device# configure terminal
  2. Configure the port-based VLAN.
    device(config)# vlan 2
  3. Add port Ethernet 1 to VLAN 2.
    device(config-vlan-2)# tagged ethe 2/1/36 ethe 12/1/38 to 12/1/39 ethe 17/2/2 ethe 55/1/32
  4. Create a VE on the VLAN.
    device(config-vlan-2)# router-interface ve 2
  5. Enter the Virtual Interface mode.
    device(config-vlan-2)# interface ve 2
  6. Enable IP Source Guard on Ethernet 2/1/36.
    device(config-vif-2)# source-guard enable ethe 2/1/36

The following example configures IP Source Guard on a virtual interface.

device# configure terminal
device(config)# vlan 2
device(config-vlan-2)# tagged ethe 2/1/36 ethe 12/1/38 to 12/1/39 ethe 17/2/2 ethe 55/1/32
device(config-vlan-2)# router-interface ve 2
device(config-vlan-2)# interface ve 2
device(config-vif-2)# source-guard enable ethernet 2/1/36

The following example configures IP Source Guard on untagged ports in a virtual interface.

device# configure terminal
device(config)# vlan 2
device(config-vlan-2)# untagged ethe 1/2/3 ethe 2/1/11 ethe 3/1/5 to 3/1/6 ethe 20/1/5 to 20/1/6 ethe 20/2/3
device(config-vlan-2)# router-interface ve 2
device(config-vlan-2)# interface ve 2
device(config-vif-2)# source-guard enable e 20/2/3