Specifications

2-630
Catalyst 4500 Series Switch Cisco IOS Command Reference—Release IOS XE 3.3.0XO(15.1(1)XO)
OL_28738 -01
Chapter 2 Cisco IOS Commands for the Catalyst 4500 Series Switches
show ip verify source
show ip verify source
To display the IP source guard configuration and filters on a particular interface, use the show ip verify
source command.
show ip verify source [interface interface_num]
Syntax Description
Defaults T his command has no default settings.
Command Modes Privileged EXE C mode
Examples These examples show how to display the IP source guard configuration and filters on a particular
interface with the show ip verify source interface command:
This output appears when DHC P snooping is enabled on VLAN s 10–20, interface fa6/1 ha s IP
source filter mode that is configured as IP, and an existing IP addres s binding 10.0.0.1 is on
VLAN 10:
Interface Filter-type Filter-mode IP-address Mac-address Vlan
--------- ----------- ----------- --------------- -------------- ---------
fa6/1 ip active 10.0.0.1 10
fa6/1 ip active deny-all 11-20
Note The second entry shows that a default PVACL (deny all IP traffic) is installed on the port for
those snooping-enabled VLA Ns that do not have a valid IP source bi nding.
This output a ppears when you enter th e show ip verify source interface f a6/2 comm and and DH CP
snooping is enabled on VLANs 10–20 , interface fa6/1 has I P source filter mode that is c onfigured
as IP, and there is an existing IP address bindin g 10.0.0.1 on VLAN 10:
Interface Filter-type Filter-mode IP-address Mac-address Vlan
--------- ----------- ----------- --------------- -------------- ---------
fa6/2 ip inactive-trust-port
This output appears when you ent er the show ip verify source inte rface fa6/3 command and the
interface fa6/3 does not have a VLAN enabled for DHCP snoopin g:
Interface Filter-type Filter-mode IP-address Mac-address Vlan
--------- ----------- ----------- --------------- -------------- ---------
fa6/3 ip inactive-no-snooping-vlan
This output appears when you ent er the show ip verify source interface fa6/4 command and the
interface fa6/4 has an IP source filter mode that is configured as IP MAC and the existing IP MAC
that binds 10.0.0.2/aa aa.bbbb.cccc on VLAN 10 and 11.0. 0.1/aaaa.bbbb.cc cd on VLAN 11:
Interface Filter-type Filter-mode IP-address Mac-address Vlan
--------- ----------- ----------- --------------- -------------- ---------
fa6/4 ip-mac active 10.0.0.2 aaaa.bbbb.cccc 10
interface interface_num (Optional) Specifies an interface.