Specifications
ip verify source
240
ip verify source
Set this command to use the terminal filter based on the DHCP snooping binding database.
(The terminal filter is functionality used to filter the packets of unregistered source IP and
MAC addresses.)
Syntax
To set or change information:
ip verify source [{port-security | mac-only}]
To delete information:
no ip verify source
Input mode
(config-if)
Parameters
{port-security | mac-only}
Sets a terminal filter condition.
port-security
Applies the terminal filter to both the source IP and the source MAC
addresses.
mac-only
Applies the terminal filter only to source MAC addresses.
1. Default value when this parameter is omitted:
The terminal filter is applied only to source IP addresses.
2. Range of values:
None
Default behavior
None
Impact on communication
If the terminal filter is applied, packets from the terminals that are not registered in the
binding database are discarded regardless of the VLAN.
When the change is applied
The change is applied immediately after setting values are changed.
Notes
1. The terminal filter functionality is disabled on trusted ports even if this command is
set.
2. If this command is set when DHCP snooping is enabled, the terminal filter
functionality is enabled even in a VLAN for which DHCP snooping is not valid.
Related commands
ip dhcp snooping
ip dhcp snooping vlan