do in conjunction with a DHCP application, probably.
IP Source Guard snoops DHCP traffic to determine which IP addresses should be seen on each physical port. then, by default, block all traffic from a port except for that IP address which it has been assigned.
links: