Glossary

IPSG

IP Source Guard

What is IPSG

IPSG (IP Source Guard) is a defense mechanism against IP address spoofing. It checks whether a device sending traffic on a given VLAN interface is who it claims to be, based on the source IP and source MAC address carried in each IP packet. The goal is straightforward: stop a malicious host from forging a legitimate host's IP address to gain unauthorized network access or launch an attack while impersonating someone else.

Without this kind of check, any device on a VLAN could simply configure itself with another host's IP address — or an address it was never assigned at all — and the network would have no way to tell the difference. IPSG closes that gap by verifying, packet by packet, that a source address actually belongs to the device sending it.

How IPSG Works

IPSG performs its legitimacy check by comparing each incoming packet's source IP and source MAC address against a set of trusted reference data already known to the switch: static binding entries an administrator configured directly, DHCP Snooping entries built from observing legitimate DHCP exchanges, and ND Snooping entries built the same way for IPv6 neighbor discovery. If a packet's source IP/MAC pair matches one of these entries, it's treated as legitimate and forwarded normally. If it doesn't match anything, the packet is considered spoofed and dropped.

This check only applies where it's actually needed. Trusted interfaces — typically the port connecting to infrastructure like a DHCP server — skip the check entirely, since traffic passing through them isn't coming from an end host that needs verifying. Untrusted interfaces, where end hosts actually connect, are where the check matters: every packet arriving there gets compared against the switch's known-good entries before being allowed onto the network.

Because the binding data IPSG checks against often comes from DHCP Snooping and ND Snooping, IPSG typically works alongside those features rather than in isolation — DHCP/ND Snooping build the trusted table of who's who, and IPSG enforces that only traffic matching that table gets through. For hosts that don't use DHCP at all — a silent terminal manually configured with a static IP, for instance — a static binding entry fills the same role, letting a legitimately configured device pass the check without ever having gone through DHCP.

Why IPSG is Beneficial

  • Blocks IP spoofing at the source: A host can't simply claim another device's IP address to bypass access controls or launch an impersonation attack, because the switch verifies the claim against data it already trusts.

  • Works for both IPv4 and IPv6: Separate IPv4 and IPv6 source-check functions mean dual-stack networks get the same protection on both address families, rather than leaving IPv6 as an afterthought.

  • Complements existing snooping infrastructure: Because IPSG checks against DHCP Snooping and ND Snooping entries a network is likely already building for other reasons, adding IPSG doesn't require standing up a separate database of legitimate hosts.

  • Selective enforcement keeps infrastructure traffic flowing: Trusted-interface configuration means the check only applies where spoofing risk actually exists — end-host-facing ports — without adding unnecessary inspection to trunk links toward servers or upstream infrastructure.

  • Covers hosts that don't use DHCP: Static binding support means devices with manually configured addresses aren't locked out just because they never went through a DHCP exchange the switch could observe.

At Asteraix

What We Can Do at Asteraix

AsterNOS implements IPSG as a per-VLAN, dual-stack security feature, configured directly through the CLI alongside DHCP Snooping and ND Snooping.

  • Independent IPv4 and IPv6 enforcement: ipv4-source-check enable and ipv6-source-check enable, configured inside VLAN configuration view, let operators turn source checking on for either address family independently — matching exactly the dual-stack scenario AsterNOS's own documentation walks through.

  • Per-interface trusted-port configuration: ipv4-source-check trusted-interface vlan <vlan-id> and the IPv6 equivalent, applied inside interface configuration view, exempt specific ports — like the one facing a DHCP server — from inspection on a given VLAN, without disabling the check anywhere else.

  • Built to work with DHCP Snooping out of the box: AsterNOS's documented deployment pattern enables DHCP relay and DHCP Snooping first, marks the server-facing port as a DHCP Snooping trusted port, and only then enables IPSG — reflecting how the feature is meant to be layered with the snooping infrastructure that feeds its legitimacy checks.

  • Direct visibility into enforcement state: ipv4-source-check config and ipv6-source-check config show, per VLAN, whether checking is active and which interfaces are currently trusted — output AsterNOS's documentation confirms directly, including packet-loss statistics that make it straightforward to verify a spoofing attempt was actually blocked rather than just assuming the configuration is working.

  • Validated against a real spoofing scenario: AsterNOS's own configuration example includes a simulated illegitimate host using another device's private IP address, alongside a legitimate silent terminal relying on a static IP — confirming IPSG correctly blocks the spoofed traffic while still allowing the manually configured, non-DHCP host through.