![Huawei AR3200 Series Configuration Manual - Lan Download Page 188](http://html.mh-extra.com/html/huawei/ar3200-series/ar3200-series_configuration-manual-lan_169302188.webp)
Networking Requirements
As shown in
, Ethernet2/0/1 and Ethernet2/0/2 of the Router are connected to LSWs.
One LSW is connected to individual users, and the other is connected to enterprise users. To
prevent MAC address attacks and limit the number of access users on the Router, configure
MAC address limiting rules on Ethernet2/0/1 and Ethernet2/0/2.
Figure 6-3
Network diagram for MAC address limiting on interfaces
Router
Eth2/0/2
Eth2/0/1
IP
network
LSW
LSW
……
Individual
user
Enterprise
user
Configuration Roadmap
The configuration roadmap is as follows:
1.
Set the limit on the number of MAC addresses learned by the interfaces.
2.
Set the action performed when the limit is reached.
Data Preparation
To complete the configuration, you need the following data:
l
Limit on the number of MAC addresses learned by Ethernet2/0/1: 4
l
Limit on the number of MAC addresses learned by Ethernet2/0/2: 100
l
Action performed when the limit is reached: discard packets with new MAC addresses and
generate an alarm
Procedure
Step 1
Configure MAC address limiting rules on the interfaces.
<Huawei>
system-view
[Huawei]
interface ethernet 2/0/1
[Huawei-Ethernet2/0/1]
mac-limit maximum 4 action discard alarm enable
[Huawei-Ethernet2/0/1]
quit
[Huawei]
interface ethernet 2/0/2
[Huawei-Ethernet2/0/2]
mac-limit maximum 100 action discard alarm enable
[Huawei-Ethernet2/0/2]
quit
Huawei AR3200 Series Enterprise Routers
Configuration Guide - LAN
6 MAC Address Table Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
177