What is IPSG
IPSG (IP Source Guard) is a defense mechanism against IP address spoofing. It checks whether a device sending traffic on a given VLAN interface is who it claims to be, based on the source IP and source MAC address carried in each IP packet. The goal is straightforward: stop a malicious host from forging a legitimate host's IP address to gain unauthorized network access or launch an attack while impersonating someone else.
Without this kind of check, any device on a VLAN could simply configure itself with another host's IP address — or an address it was never assigned at all — and the network would have no way to tell the difference. IPSG closes that gap by verifying, packet by packet, that a source address actually belongs to the device sending it.
How IPSG Works
IPSG performs its legitimacy check by comparing each incoming packet's source IP and source MAC address against a set of trusted reference data already known to the switch: static binding entries an administrator configured directly, DHCP Snooping entries built from observing legitimate DHCP exchanges, and ND Snooping entries built the same way for IPv6 neighbor discovery. If a packet's source IP/MAC pair matches one of these entries, it's treated as legitimate and forwarded normally. If it doesn't match anything, the packet is considered spoofed and dropped.
This check only applies where it's actually needed. Trusted interfaces — typically the port connecting to infrastructure like a DHCP server — skip the check entirely, since traffic passing through them isn't coming from an end host that needs verifying. Untrusted interfaces, where end hosts actually connect, are where the check matters: every packet arriving there gets compared against the switch's known-good entries before being allowed onto the network.
Because the binding data IPSG checks against often comes from DHCP Snooping and ND Snooping, IPSG typically works alongside those features rather than in isolation — DHCP/ND Snooping build the trusted table of who's who, and IPSG enforces that only traffic matching that table gets through. For hosts that don't use DHCP at all — a silent terminal manually configured with a static IP, for instance — a static binding entry fills the same role, letting a legitimately configured device pass the check without ever having gone through DHCP.
Why IPSG is Beneficial
Blocks IP spoofing at the source: A host can't simply claim another device's IP address to bypass access controls or launch an impersonation attack, because the switch verifies the claim against data it already trusts.
Works for both IPv4 and IPv6: Separate IPv4 and IPv6 source-check functions mean dual-stack networks get the same protection on both address families, rather than leaving IPv6 as an afterthought.
Complements existing snooping infrastructure: Because IPSG checks against DHCP Snooping and ND Snooping entries a network is likely already building for other reasons, adding IPSG doesn't require standing up a separate database of legitimate hosts.
Selective enforcement keeps infrastructure traffic flowing: Trusted-interface configuration means the check only applies where spoofing risk actually exists — end-host-facing ports — without adding unnecessary inspection to trunk links toward servers or upstream infrastructure.
Covers hosts that don't use DHCP: Static binding support means devices with manually configured addresses aren't locked out just because they never went through a DHCP exchange the switch could observe.