Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?


ip-source-guard (MX Series)


Hierarchy Level


Perform IP source guard checking on packets sent from access interfaces. Validate source IP addresses and source MAC addresses on all bridge domains or on the specified bridge domain or bridge domain range. Forward packets with valid addresses and drop those with invalid addresses.

  • ip-source-guard—Enable IP source guard checking.

If you configure IP source guard at the [edit bridge-domains bridge-domain-name forwarding-options dhcp-security] hierarchy level:

  • IP source guard can be configured only for a specific bridge domain, not for a list or range of bridge domains.

  • DHCP snooping is automatically enabled.

Required Privilege Level

system—To view this statement in the configuration.

system-control—To add this statement to the configuration.

Release Information

Hierarchy level [edit bridge-domains bridge-domain-name forwarding-options dhcp-security] introduced in Junos OS Release 14.1 for the MX Series.