IP Source Guard Flashcards

1
Q

What is IP source guard?

A

Similar to DAI but applied to all traffic, it ensures that packets sent from an interface must have a source IP that matches the switch’s table.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What happens when a host first connects to an ip source guard-enabled port?

A

All traffic besides DHCP packets are blocked. The switch will then map the received DHCP IP to that interface.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

How does IP source guard enforce address binding?

A

With automatically-written VLAN ACLs.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What must be enabled for IP source guard to work?

A

DHCP snooping.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

IP source guard is enabled at what level?

A

The interface level.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What interface-line command enables IP source guard?

A

“ip verify”

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What additional options can be configured with IP source guard, and what do they do?

A

Port-security, verifies the source MAC address; smartlog, sends the offending frames to a remote server.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Can IP source guard entries be added statically?

A

Yes, with the “ip source binding” command.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What can hosts NOT do when IP source guard is enabled?

A

Static their IP address.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly