Get the App
SLTechnology News&Howtos  ›  Network Security  › 

IPSource Guard experiment

Shulou Source: shulou.com Published: 2022-06-01 07:22:31 10月04日 Update

Experiment 5: IPSource Guard

1. Do this experiment on the basis of experiment 3

two。 Enable IPSource Guard on the Fa0/1 interface of SW1

Test the connectivity of R1ping 10.1.1.3 and 10.1.1.4, because there is DHCPsnooping, it is no problem.

3. Enable IPSource Guard on the Fa0/3 interface of SW1

Re-test the connectivity between R1 and R3

4. Bind table items statically on SW1. Enable R1 and R3 to communicate.

5. Change the MAC address of R3 and observe the communication between R1 and R3. What should you do if you want IPSource Guard to check both IP and MAC?

SW1 (config) # int f0bin1

SW1 (config-if) # ip verify source / / R1ping R3; pingR4

SW1 (config) # int f0bin3

SW1 (config-if) # ip verify source / / R1ping R3 is not available. Source protection only releases entries in the snooping binding table.

SW1 (config) # ip source binding 000c.ce3a.b7e0 vlan 10 int f0swap 3 / / static add entry, R1ping R3 pass

R3 (config) # int f0Let0

R3 (config-if) # mac-address 3.3.3.3 / / modify the mac of R3

SW1 (config) # int f0bin3

SW1 (config-if) # switchport port-security / / Port-security must be enabled first

SW1 (config-if) # ip verify source port-security / / R1ping R3 does not work

SW1#sh ip verify source / / View the correspondence between API and ip

Tags: Experiment interface entry static test communication at the same time address foundation situation problem inspection observation protection Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno MariaDB Apple Microsoft Huawei OPPO Reno