To bind static MAC address 1010-1010-1010 to service port 1, and set the maximum number
of learnable MAC addresses to 0, that is, service port 1 permits only the packet whose source
MAC address is 1010-1010-1010, do as follows:
huawei(config)#
mac-address static service-port 1 1010-1010-1010
huawei(config)#
mac-address max-mac-count service-port 1 0
3.11.3 Preventing the Attack of Invalid Users
This topic describes how to configure anti-IP spoofing and anti-MAC spoofing to prevent
malicious users from attacking legal users by forging the IP address and MAC address of the
legal users.
Context
Anti-IP spoofing is to dynamically trigger the IP address binding, thus preventing illegal users
from stealing the IP address of legal users. When anti-IP spoofing is enabled, a user port is bound
to an IP address after the user goes online. Then, the user cannot go online through this port by
using other IP addresses, and any user cannot go online through other ports by using this IP
address.
The major function of anti-MAC spoofing is to prevent illegal users from forging the MAC
address of legal users. The purpose is to ensure that the service of legal users is not affected.
Anti-MAC spoofing is mainly applied to PPPoE and DHCP access users.
Procedure
l
Configure anti-IP spoofing.
The anti-IP spoofing function can be enabled or disabled at two levels. The anti-IP spoofing
function is enabled only when it is enabled at both levels.
–
Global function: Run the
security anti-ipspoofing
command to configure the global
function. By default, the global function is disabled.
–
VLAN-level function:
1.
Run the
vlan service-profile
command to create a VLAN service profile and enter
the VLAN service profile mode.
2.
Run the
security anti-ipspoofing
command to configure the VLAN-level
function. By default, the VLAN-level function is disabled.
3.
Run the
commit
command to make the profile configuration take effect. The
configuration of the VLAN service profile takes effect only after this command is
executed.
4.
Run the
quit
command to quit the VLAN service profile mode.
5.
Run the
vlan bind service-profile
command to bind the VLAN service profile
configured in
NOTE
When anti-IP spoofing is enabled after a user is already online, the IP address of this user is not bound by
the system. As a result, the service of this user is interrupted, this user goes offline, and the user needs to
go online again. Only the user who goes online after anti-IP spoofing is enabled can have the IP address
bound.
l
Configure anti-MAC spoofing.
SmartAX MA5616 Multi-service Access Module
Configuration Guide
3 Basic Configuration
Issue 04 (2011-10-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
92