Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Dell EMC Configuration Guide for the S4048T–ON System 9.14.2.4

PDF

Enabling IP+MAC Source Address Validation

IP source address validation (SAV) validates the IP source address of an incoming packet and optionally the VLAN ID of the client against the DHCP snooping binding table. IP+MAC SAV ensures that the IP source address and MAC source address are a legitimate pair, rather than validating each attribute individually. You cannot configure IP+MAC SAV with IP SAV.
  1. Allocate at least one FP block to the ipmacacl CAM region.
    CONFIGURATION mode
    cam-acl l2acl
  2. Save the running-config to the startup-config.
    EXEC Privilege mode
    copy running-config startup-config
  3. Reload the system.
    EXEC Privilege
    reload
  4. Do one of the following.
    • Enable IP+MAC SAV.

      INTERFACE mode

      ip dhcp source-address-validation ipmac

    • Enable IP+MAC SAV with VLAN option.

      INTERFACE mode

      ip dhcp source-address-validation ipmac vlan vlan-id

Dell EMC Networking OS creates an ACL entry for each IP+MAC address pair and optionally with its VLAN ID in the binding table and applies it to the interface.

To display the IP+MAC ACL for an interface for the entire system, use the show ip dhcp snooping source-address-validation [interface] command in EXEC Privilege mode.


Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\