l
To prevent hackers from using MAC addresses to attack the network, configure a static
MAC address entry for each user host on the Router. Set the aging time for the dynamic
MAC address entries to 500 seconds.
l
To prevent hackers from stealing user information by forging the MAC address of the
server, configure a static MAC address entry on the Router for the server.
Figure 6-1
Network diagram
Server
Router
MAC:
0004-0004-0004
Eth2/0/2
VLAN2
Eth2/0/1
VLAN2
LSW
PC1
PC2
MAC:
0002-0002-0002
MAC:
0003-0003-0003
Configuration Roadmap
The configuration roadmap is as follows:
1.
Create VLANs on the Router and add the interfaces to the VLANs.
2.
Configure static MAC address entries.
3.
Set the aging time for the dynamic MAC address entries.
Data Preparation
To complete the configuration, you need the following data:
l
MAC address of PC1: 0002-0002-0002
l
MAC address of PC2: 0003-0003-0003
l
MAC address of the server: 0004-0004-0004
l
VLAN that the Router belongs to: VLAN 2
l
Interface connected to the LSW: Ethernet2/0/1
l
Interface connected to the server: Ethernet2/0/2
l
Aging time for dynamic entries: 500 seconds
Huawei AR3200 Series Enterprise Routers
Configuration Guide - LAN
6 MAC Address Table Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
173