8
interface interface-type interface-number
3.
Set the MAC learning limit on the interface.
mac-address max-mac-count
count
By default, no MAC learning limit is configured on a port.
Configuring the unknown frame forwarding rule
after the MAC learning limit is reached
In this document, unknown frames refer to frames whose source MAC addresses are not in the MAC
address table.
About unknown frame forwarding rule configuration
You can enable or disable forwarding of unknown frames after the MAC learning limit is reached.
Procedure
1.
Enter system view.
system-view
2.
Enter Layer 2 Ethernet interface view.
interface
interface-type interface-number
3.
Configure the device to forward unknown frames received on the interface after the MAC
learning limit on the interface is reached.
mac-address max-mac-count enable-forwarding
By default, the device can forward unknown frames received on an interface after the MAC
learning limit on the interface is reached.
Assigning MAC learning priority to interfaces
About MAC learning priority mechanism
The MAC learning priority mechanism assigns either low priority or high priority to an interface. An
interface with high priority can learn MAC addresses as usual. However, an interface with low priority
is not allowed to learn MAC addresses already learned on a high-priority interface.
The MAC learning priority mechanism can help defend your network against MAC address spoofing
attacks. In a network that performs MAC-based forwarding, an upper layer device MAC address
might be learned by a downlink interface because of a loop or attack to the downlink interface. To
avoid this issue, perform the following tasks:
•
Assign high MAC learning priority to an uplink interface.
•
Assign low MAC learning priority to a downlink interface.
Procedure
1.
Enter system view.
system-view
2.
Enter interface view.
{
Enter Layer 2 Ethernet interface view.
interface interface-type interface-number
{
Enter Layer 2 aggregate interface view.
interface bridge-aggregation interface-number
3.
Assign MAC learning priority to the interface.
Summary of Contents for S6850 Series
Page 108: ...48 WGE1 0 3 32768 49153 50100 0x7b 0001 0001 0001 ACDEF...
Page 259: ...21 6 N A 200 6...
Page 337: ...ii...