<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Disable Static IP Source Guard in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/how-to-disable-static-ip-source-guard/m-p/4683376#M7082</link>
    <description>&lt;P&gt;it work, without max command,&amp;nbsp;&lt;BR /&gt;but let me check how can I solve this issue&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 08 Sep 2022 09:33:35 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2022-09-08T09:33:35Z</dc:date>
    <item>
      <title>How to Disable Static IP Source Guard</title>
      <link>https://community.cisco.com/t5/endpoint-security/how-to-disable-static-ip-source-guard/m-p/4683275#M7079</link>
      <description>&lt;P&gt;Hello.&lt;BR /&gt;&lt;BR /&gt;We are trying to configure DHCP snooping and IP source guard on our L2SW to perform dynamic IP address inspection.&lt;BR /&gt;&lt;BR /&gt;I have completed both configurations and the end node is able to get an address via DHCP.&lt;BR /&gt;&lt;BR /&gt;However, normal communication seems to be blocked by L2SW unless I set the "ip device tracking maximum " command in interface configuration mode.&lt;BR /&gt;&lt;BR /&gt;I am aware that this is the behavior of static IP source guard, but we only have dynamic IP source guard configured on each port.&lt;BR /&gt;&lt;BR /&gt;Is it possible to get DHCP snooping and dynamic IP source guard to work without setting the "ip device tracking maximum" command?&lt;BR /&gt;&lt;BR /&gt;Environment&lt;BR /&gt;Cisco Modeling Labs&lt;BR /&gt;&lt;BR /&gt;L2SW -&amp;gt; IOSvL2 version 15.2&lt;BR /&gt;&lt;BR /&gt;config&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;L2SW
!
ip dhcp snooping vlan 103
no ip dhcp snooping information option
ip dhcp snooping
!
interface GigabitEthernet0/3
switchport access vlan 103
switchport mode access
negotiation auto
ip verify source
!&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&amp;nbsp;Obviously, I have not explained it well enough. If you need any additional information, please feel free to ask.&lt;BR /&gt;&lt;BR /&gt;Thank you in advance.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2022 08:34:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/how-to-disable-static-ip-source-guard/m-p/4683275#M7079</guid>
      <dc:creator>Koki Satani</dc:creator>
      <dc:date>2022-09-08T08:34:28Z</dc:date>
    </item>
    <item>
      <title>Re: How to Disable Static IP Source Guard</title>
      <link>https://community.cisco.com/t5/endpoint-security/how-to-disable-static-ip-source-guard/m-p/4683335#M7080</link>
      <description>&lt;P&gt;That should work with out that command.&lt;/P&gt;
&lt;P&gt;If a switch port is connected to a DHCP server, configure a port as trusted by entering the &lt;STRONG class="cBold"&gt; ip dhcp snooping trust &lt;/STRONG&gt; interface configuration command.&lt;/P&gt;
&lt;P&gt;end device PC or single device.&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;&lt;SPAN&gt;&amp;nbsp; ip verify source vlan dhcp-snooping&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;some reference guide :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3750x_3560x/software/release/15-0_2_se/configuration/guide/3750x_cg/swdhcp82.html#wp1078853" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3750x_3560x/software/release/15-0_2_se/configuration/guide/3750x_cg/swdhcp82.html#wp1078853&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2022 09:22:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/how-to-disable-static-ip-source-guard/m-p/4683335#M7080</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2022-09-08T09:22:24Z</dc:date>
    </item>
    <item>
      <title>Re: How to Disable Static IP Source Guard</title>
      <link>https://community.cisco.com/t5/endpoint-security/how-to-disable-static-ip-source-guard/m-p/4683372#M7081</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;I actually tried to type that command, but it seems to be unconfigurable.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="KokiSatani_1-1662629240947.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/161792i0224104667A7BB2F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="KokiSatani_1-1662629240947.png" alt="KokiSatani_1-1662629240947.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2022 09:27:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/how-to-disable-static-ip-source-guard/m-p/4683372#M7081</guid>
      <dc:creator>Koki Satani</dc:creator>
      <dc:date>2022-09-08T09:27:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to Disable Static IP Source Guard</title>
      <link>https://community.cisco.com/t5/endpoint-security/how-to-disable-static-ip-source-guard/m-p/4683376#M7082</link>
      <description>&lt;P&gt;it work, without max command,&amp;nbsp;&lt;BR /&gt;but let me check how can I solve this issue&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2022 09:33:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/how-to-disable-static-ip-source-guard/m-p/4683376#M7082</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-09-08T09:33:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to Disable Static IP Source Guard</title>
      <link>https://community.cisco.com/t5/endpoint-security/how-to-disable-static-ip-source-guard/m-p/4683413#M7083</link>
      <description>&lt;P&gt;Thanks for the confirmation.&lt;/P&gt;&lt;P&gt;Below is more detailed information on the configuration I am using for verification.&lt;/P&gt;&lt;P&gt;・The L2SW is a floor switch and DHCP packets are relayed by the core switch on the uplink.&lt;/P&gt;&lt;P&gt;・DHCP snooping is set only on the floor switch.&lt;/P&gt;&lt;P&gt;・DHCP server is created by IOSv.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2022 09:42:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/how-to-disable-static-ip-source-guard/m-p/4683413#M7083</guid>
      <dc:creator>Koki Satani</dc:creator>
      <dc:date>2022-09-08T09:42:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to Disable Static IP Source Guard</title>
      <link>https://community.cisco.com/t5/endpoint-security/how-to-disable-static-ip-source-guard/m-p/4683558#M7084</link>
      <description>&lt;P&gt;&lt;SPAN&gt;there are two check&amp;nbsp;&lt;BR /&gt;static which you need the below&amp;nbsp;&lt;BR /&gt;""You must configure the&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;ip device tracking&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;maximum&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;limit-number&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;interface configuration command globally for IPSG for static hosts to work. If you only configure this command on a port without enabling IP device tracking globally or by setting an IP device tracking maximum on that interface, IPSG with static hosts rejects all the IP traffic from that interface.""&lt;BR /&gt;&lt;BR /&gt;dynamic which depend on DHCP snooping (which you already run)&lt;BR /&gt;here you need to config &lt;STRONG&gt;ip verify source vlan dhcp snooping&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;FONT color="#00FF00"&gt;I see you run static and that why you need max command&amp;nbsp;&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Sep 2022 11:36:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/how-to-disable-static-ip-source-guard/m-p/4683558#M7084</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-09-08T11:36:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to Disable Static IP Source Guard</title>
      <link>https://community.cisco.com/t5/endpoint-security/how-to-disable-static-ip-source-guard/m-p/4684534#M7090</link>
      <description>&lt;P&gt;note that CML image IOSvL2 version 15.2 may not support this feature even if commands are there !&lt;/P&gt;
&lt;P&gt;not all features are supported by CML switch image, especially switch images; and some features could be tricky or misbehaving.&lt;/P&gt;
&lt;P&gt;Regards, ML&lt;BR /&gt;**Please Rate All Helpful Responses **&lt;/P&gt;</description>
      <pubDate>Sat, 10 Sep 2022 01:36:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/how-to-disable-static-ip-source-guard/m-p/4684534#M7090</guid>
      <dc:creator>Martin L</dc:creator>
      <dc:date>2022-09-10T01:36:53Z</dc:date>
    </item>
  </channel>
</rss>

