< Home

ipsg enable (AP wired port profile view)

Function

The ipsg enable command enables IP source guard (IPSG) on an AP's wired interface.

The undo ipsg enable command disables IPSG on an AP's wired interface.

By default, IPSG is disabled on an AP's wired interface.

Format

ipsg enable

undo ipsg enable

Parameters

None

Views

AP wired port profile view

Default Level

2: Configuration level

Usage Guidelines

Usage Scenario

Attackers often use packets with the source IP addresses or MAC addresses of authorized users to access or attack networks. As a result, authorized users cannot obtain stable and secure network services. You can enable the IPSG function to prevent the situation.

Prerequisites

Terminal address learning has been enabled on the AP's wired interface using the learn-client-address enable command.

Follow-up Procedure

Bind the AP wired port profile to an AP group or AP.

Precautions

This command takes effect only on IP packets transmitted on an AP's wired interface.

The AP wired interfaces added to an Eth-trunk interface do not support this function.

Example

# Enable IPSG on an AP's wired interface.

<HUAWEI> system-view
[HUAWEI] wlan
[HUAWEI-wlan-view] wired-port-profile name wire1
[HUAWEI-wlan-wired-port-wire1] ipsg enable
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >