162• A dynamic binding is implemented in cooperation with DHCP snooping or DHCP Relay. It issuitable when there are many hosts in a LAN, and DHCP is used to allocate IP addresses tothe hosts. Once DHCP allocates an IP address for a user, the IP source guard function willautomatically add a binding entry based on the DHCP entry to allow the user to access thenetwork. If a user specifies an IP address instead of getting one through DHCP, the user willnot trigger DHCP to allocate an IP address, and therefore no IP source guard binding will beadded for the user to access the network. In this way, IP address collision and theft areprevented.You cannot configure the IP source guard function on a port in an aggregation group, nor can you add aport configured with IP source guard to an aggregation group.Configuring a static IP source guard bindingentryFollow these steps to configure a static IP source guard binding entry:To do… Use the command… Remarks1. Enter system view system-view —2. Enter Ethernet interface view interface interface-type interface-number —3. Configure a static IP sourceguard binding entryuser-bind { ip-address ip-address |ip-address ip-address mac-addressmac-address | mac-address mac-address } [ vlan vlan-id ]RequiredNo static IP source guardbinding entry exists bydefault.• You cannot configure the same static binding entry on one port for multiple times, but you can configurethe same static entry on different ports.• In an IP source guard binding entry, the MAC address cannot be all 0s, all Fs (a broadcast address), ora multicast address, and the IP address can only be a Class A, Class B, or Class C address and can beneither 127.x.x.x nor 0.0.0.0.