Hi everyone,
I've been reading about IP Source Guard configuration in the SWITH FLG (p.370 - 371). I fired up a 3550, then a 3560, looking for the command #ip verify source vlan dhcp-snooping and all that seems to be supported is #ip verify source port-security. So I did some research and it appears that the "vlan dhcp-snooping" command set is only available on the 6500. Why on earth has this been included in the FLG is beyond me.
I'm assuming if I learn the commands that are available e.g. #ip verify source port-security I should be safe right?
#switchport port-security limit rate isn't available either.
Here is some great documentation on these topics:
IPSG on 6500:
http://www.cisco.com/en/US/docs/switches/lan/catalyst6500/ios/12.2SX/configuration/guide/ipsrcgrd.pdf
IPSG + DHCP Snooping on 2960:
http://www.cisco.com/en/US/docs/switches/lan/catalyst2960/software/release/12.2_52_se/configuration/guide/swdhcp82.pdf