SV-220685r1156799_rule
V-220685
SRG-NET-000362-L2S-000026
CISC-L2-000140
CAT II
10
Configure the switch to have IP Source Guard enabled on all user-facing or untrusted access switch ports.
SW1(config)# int e1/1-32
SW1(config-if-range)# ip verify source dhcp-snooping-vlan
Review the switch configuration to verify IP Source Guard is enabled on all user-facing or untrusted access switch ports as shown in the example below:
interface Ethernet1/1
ip verify source dhcp-snooping-vlan
interface Ethernet1/2
ip verify source dhcp-snooping-vlan
…
…
…
interface Ethernet1/32
ip verify source dhcp-snooping-vlan
Note: The IP Source Guard feature depends on the entries in the DHCP snooping database or static IP-MAC-VLAN configuration commands to verify IP-to-MAC address bindings.
Note: This requirement is not applicable for switch ports configured for 802.1x or Mac Address Bypass.
If the switch does not have IP Source Guard enabled on all untrusted access switch ports, this is a finding.
V-220685
False
CISC-L2-000140
Review the switch configuration to verify IP Source Guard is enabled on all user-facing or untrusted access switch ports as shown in the example below:
interface Ethernet1/1
ip verify source dhcp-snooping-vlan
interface Ethernet1/2
ip verify source dhcp-snooping-vlan
…
…
…
interface Ethernet1/32
ip verify source dhcp-snooping-vlan
Note: The IP Source Guard feature depends on the entries in the DHCP snooping database or static IP-MAC-VLAN configuration commands to verify IP-to-MAC address bindings.
Note: This requirement is not applicable for switch ports configured for 802.1x or Mac Address Bypass.
If the switch does not have IP Source Guard enabled on all untrusted access switch ports, this is a finding.
M
4073