Disable IPSG on S series switches


To disable the IPSG function on an S series switch (except the S1700), run the undo ip source check user-bind enable command in the VLAN or interface view.

Other related questions:
Enable and disable PoE on an S series switch
Enable or disable the PoE function on S series switches:

1. By default, the PoE function is enabled on an interface
2. Enable or disable PoE power supply.
[HUAWEI]interface gigabitethernet 1/0/0
[HUAWEI-GigabitEthernet1/0/0]undo poe enable  //Disable PoE power supply.
[HUAWEI-GigabitEthernet1/0/0]poe enable       //Enable PoE power supply.

The downlink electrical interfaces of PoE switches support PoE power supply, with up to 30 W power on each interface. The maximum power supply distance is 100 m.
Only ES0D0G48VA00 (S7700)/LE0DG48VEA00 (S9300) cards of modular switches (S7700/S9700/S9300/S12700) support PoE power supply.

If the switch connects to 48 V standard PoE powered devices but cannot negotiate power supply capabilities with the devices, you can run poe force-power on the interfaces to forcibly power on the devices.

Configure binding tables for IPSG (user-bind binding tables) on S series switches
Configure a binding table for IPSG (user-bind binding table) on an S series switch (except the S1700) as follows: �?Static binding table A static binding entry contains at least one of the following: IP address, MAC address, interface, VLAN, and IP address and MAC address. An interface cannot be bound to a VLAN to form a binding entry. For example, configure a static binding entry of VLAN 2 and IP address [HUAWEI] user-bind static ip-address vlan 2 Note: Static binding entries can be configured only in the system view. �?Dynamic binding table Enable DHCP snooping globally and on an interface. Generally, the interface directly or indirectly connected to the DHCP server or gateway is configured as a trusted interface. After DHCP snooping is enabled and the trusted interface is configured, user-side interfaces automatically generate dynamic binding entries based on received DHCP ACK packets. For example, enable DHCP snooping globally and on GE0/0/1, and configure G0/0/1 as a trusted interface. [HUAWEI] dhcp enable [HUAWEI] dhcp snooping enable [HUAWEI] interface gigabitethernet 0/0/1 [HUAWEI-GigabitEthernet0/0/1] dhcp snooping enable [HUAWEI-GigabitEthernet0/0/1] dhcp snooping trusted Note: If both DHCP relay and VRRP are configured on a switch, DHCP snooping cannot be enabled. DHCP snooping cannot be enabled if the DHCP server is at the subordinate VLAN side and the DHCP client is at the principle VLAN side. After DHCP snooping is configured, the switch generates DHCP snooping entries for the hosts when the hosts go online again. Then IPSG takes effect. If you enable IPSG before the switch generates DHCP snooping dynamic binding entries, the switch rejects all packets except DHCP Request packets. In this situation, the hosts with dynamic IP addresses cannot communicate with each other. Therefore, before enabling the IPSG function, configure the DHCP snooping function to enable the switch to generate dynamic binding entries.

If you have more questions, you can seek help from following ways:
To iKnow To Live Chat
Scroll to top