S Layer 2 Managed Switch User Manual
陈泽科技有限公司
www.stephen-tele.com
19
MAC address banding and 802.1X function.
FDB(ARL) table max aging time:
Forwarding(FDB/ARL) table of S supports automatic learning and static configuration. For dynamic learning forward
table item, if the switch does not receive any source MAC and VID data from this table, this item will be deleted by the switch.
This time range is called max aging time of forwarding table. For static configuration table item, it will not be aged unless user
deletes this item manually.
DLF Data Package:
All unicast packet that go through the switch will find transmitting port according to MAC+VID search forwarding table. If
there is no relative forwarding table item that correspond to this MAC+VID in this forwarding table, switch will broadcast this
unicast packet to all VLAN ports. We call this kind of data package as DLF or UL packet.
4.3.5 MAC address binding
S supports MAC address binding based on port which ensure safety of network user access. User is connected to
the network through port of switch. If some port binds with some specific MAC address in the switch, then this MAC address
is a legal MAC address. Switch will allow legal MAC addresses connect to network and prohibit illegal MAC addresses in order
to realize safe access. Actually MAC address binding in configuration port is writing some specific MAC address to forwarding
table statically.
If switch is bound with some MAC address, switch will keep on checking the data flow that goes through this port. If source
MAC address of this data flow is legal, this data will be allowed to forward. If source MAC address is illegal, this data package
will be rejected.
In the topology of this figure, there is a non-management switch under port 10 of
S
and two hosts A and B are
connected with the non-management switch. MAC address of A is 00:00:00:00:00:01, while MAC address of B is
00:00:00:00:00:02. PVID of
S
’s port 10 is 1. We bind MAC address 00:00:00:00:00:01, VID 1 with port 10. All data
packet that go through from non-management switch to
S
will be checked by switch. Host A can visit WWW
through
S
since all data with source MAC 00:00:00:00:00:01 and PVID of port is 1. But for host B, it can not visit
WWW since its MAC address was not bind with port 10 of switch.
In the binding of MAC address with
S
port, switch will check VLAN ID as well when it is checking source MAC since
the learning mechanism of address table is IVL mode. If data packet without VLAN TAG, switch will check it according to PORT
VID of flow-in port. If data packet with VLAN TAG, switch will check it according to the VLAN ID that carried by VLAN TAG.