MAC Address Validation
MAC address validation is a verification process performed on each incoming packet
to prevent spoofing on IP Ethernet-based interfaces, including bridged Ethernet
interfaces. When an incoming packet arrives on a layer 2 interface, the validation
table is used to compare the packet’s source IP address with its MAC address. If the
MAC address and IP address match, the packet is forwarded; if it does not match,
the packet is dropped.
NOTE:
MAC address validation for bridged Ethernet interfaces is supported only on
OC12 ATM line modules on ERX routers and on OC3/OC12 ATM IOAs on the E120
and E320 routers.
MAC address validation on the E Series router can be accomplished in two ways:
■
You can statically configure it on a physical interface via the
arp validate
command
■
You can enable DHCP to perform the function independently and dynamically.
See
JUNOSe Link Layer Configuration Guide
.
The
arp validate
command adds the IP-MAC address pair to the validation table
maintained on the physical interface.
If the validation is added statically via the CLI, the IP address–MAC address pairs are
stored in NVS. The entries are used for MAC validation only if MAC validation is
enabled on the interface via the
ip mac-validate
command.
CAUTION:
When you configure an interface using the
arp validate
command, you
cannot overwrite the ARP values that were added by DHCP.
You can enable or disable MAC address validation on a per interface basis by issuing
the
ip mac-validate
command. See
JUNOSe Physical Layer Configuration Guide
or
JUNOSe Link Layer Configuration Guide
for information.
A dynamic IP subscriber interface inherits the MAC address validation state (enabled
or disabled) configured for its parent static primary IP interface. See
Configuring
Subscriber Interfaces
in the
JUNOSe Broadband Access Configuration Guide
for
information.
arp validate
■
Use to add IP address–MAC address validation pairs. When validation is enabled,
all packets with the source IP address received on this IP interface are validated
against the IP-MAC entries.
■
To add a validation pair, specify one of the following:
■
ipAddress
and
macAddress
of the interface
22
■
Address Resolution Protocol
JUNOSe 11.0.x IP, IPv6, and IGP Configuration Guide
Summary of Contents for IGP - CONFIGURATION GUIDE V11.1.X
Page 6: ...vi...
Page 8: ...viii JUNOSe 11 0 x IP IPv6 and IGP Configuration Guide...
Page 18: ...xviii List of Figures JUNOSe 11 0 x IP IPv6 and IGP Configuration Guide...
Page 20: ...xx List of Tables JUNOSe 11 0 x IP IPv6 and IGP Configuration Guide...
Page 26: ...2 Internet Protocol JUNOSe 11 0 x IP IPv6 and IGP Configuration Guide...
Page 228: ...204 Internet Protocol Routing JUNOSe 11 0 x IP IPv6 and IGP Configuration Guide...
Page 264: ...240 Monitoring RIP JUNOSe 11 0 x IP IPv6 and IGP Configuration Guide...
Page 438: ...414 Monitoring IS IS JUNOSe 11 0 x IP IPv6 and IGP Configuration Guide...
Page 439: ...Part 3 Index Index on page 417 Index 415...
Page 440: ...416 Index JUNOSe 11 0 x IP IPv6 and IGP Configuration Guide...
Page 454: ...430 Index JUNOSe 11 0 x IP IPv6 and IGP Configuration Guide...