ZXA10 C300 Configuration Manual (CLI)
Result
When the subscriber sends NDP protocol packets, the system adds the following LIO field
to the packets:
Circuit-id: ZXA10-C300/ZTE eth 5/1/1/0/1:10
//where, 10 is original user VLAN.
14.2 MAC Address Anti-Spoofing Configuration
The ZXA10 C300 supports the MAC address anti-spoofing function to prevent malicious
MAC address spoofing, which affects the network security.
The ZXA10 C300 MAC address anti-spoofing function has the following features:
l
This function constrains the user port that learns the MAC address. When one MAC
address is learnt by one user port, the address cannot be learnt by other user ports.
Thus, the same MAC address cannot float between different ports.
l
Once a user port is detected trying MAC address spoofing, an alarm message
including the port and MAC address will be reported.
l
This function supports uplink port protection. A user port MAC address can float to
an uplink port, whereas an uplink port address cannot float to a user port. A MAC
address can float between uplink ports, thus to protect the gateway MAC address of
the uplink ports.
14.2.1 Configuring the User Port MAC Address Anti-Spoofing
User-port MAC address anti-spoofing prevents malicious MAC address spoofing between
user ports.
Context
The user-port MAC address anti-spoofing has the following features:
l
When one MAC address is learnt by one user port, the address cannot be learnt by
other user ports.
l
Once there is a MAC move event at the first time, the system will generate a notification
including the MAC address, VLAN, move-to-port and move-from-port.
l
The notification report interval of the same MAC move events can be configured.
Steps
1.
Enable global MAC address anti-spoofing function.
ZXAN(config)#security mac-anti-spoofing enable
2.
Enable MAC move notification control.
ZXAN(config)#security mac-move-report enable
3.
(Optional) Configure the notification report interval of the same MAC move log.
ZXAN(config)#security mac-move-report interval 30
14-8
SJ-20130520164529-007|2013-06-30 (R1.0)
ZTE Proprietary and Confidential