Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

Navigation

ip-source-guard

Syntax

(ip-source-guard | no-ip-source-guard);

Hierarchy Level

Release Information

Statement introduced in Junos OS Release 9.2 for EX Series switches.

Description

Perform IP source guard checking on packets sent from access interfaces. Validate source IP addresses and source MAC addresses on all VLANs or on the specified VLAN or VLAN range. Forward packets with valid addresses and drop those with invalid addresses.

  • ip-source-guard—Enable IP source guard checking.
  • no-ip-source-guard—Disable IP source guard checking.

Note:

Before you configure IP source guard, be sure that you have:

Explicitly enabled DHCP snooping on the specific VLAN or specific VLANs on which you will configure IP source guard. See Enabling DHCP Snooping (CLI Procedure). If you configure IP source guard on specific VLANs rather than on all VLANs, you must also enable DHCP snooping explicitly on those VLANs. Otherwise, the default value of no DHCP snooping applies to that VLAN.

Default

Disabled.

Required Privilege Level

system—To view this statement in the configuration.

system-control—To add this statement to the configuration.

Published: 2012-12-07