
OLT2406 User’s Guide
504
C
HAPTER
70
Port Security
70.1 Port Security Overview
Port security allows only packets with dynamically learned MAC addresses and/or configured static
MAC addresses to pass through a port on the OLT. The OLT can learn up to 32K MAC addresses in total
with no limit on individual ports other than the sum cannot exceed 32K.
For maximum port security, enable this feature, disable MAC address learning and configure static MAC
address(es) for a port. It is not recommended you disable port security together with MAC address
learning as this will result in many broadcasts. By default, MAC address learning is still enabled even
though port security is not activated.
With port-security enabled on the OLT, each subscriber port counts the number of newly learnt MAC
addresses. Configure the number of MAC addresses a specific port can learn and the OLT drops Source
Lookup Failure (SLF) packets on the port that exceed the limit.
Anti-MAC spoofing lets you set whether or not to allow a subscriber device to move between OLT
subscriber ports. This means the OLT has learned a subscriber device’s source MAC address at one port
but receives packets containing the same source MAC address through another subscriber port before
the learned MAC address times out from the MAC address table. Disable anti-MAC spoofing to have
the OLT allow the port move and learn the source MAC address on the new port. Enable anti-MAC
spoofing to have the OLT drop the packets and not learn the source MAC address on the new port.
Anti-MAC spoofing applies to the subscriber ports, not the uplink ports.
70.2 Port Security Commands
The following table lists the port security commands.
Table 255 Port Security Commands
COMMAND
DESCRIPTION
M
P
port-security
Enables the port security feature.
C
13
port-security <
aid
>
Enables port security on the specified port.
aid
:
<msc|ge|pon>-<
slot
>-<
port
>
C
13
no port-security
Disables the port security feature.
C
13
no port-security <
aid
>
Disables port security on the specified port.
aid
:
<msc|ge|pon>-<
slot
>-<
port
>
C
13
Summary of Contents for OLT2406
Page 4: ...Document Conventions OLT2406 User s Guide 4 Desktop Laptop Switch IP Phone Smart T V...
Page 32: ...Table of Contents OLT2406 User s Guide 32 Index 758...
Page 33: ...33 PART I Introduction and Hardware Installation...
Page 63: ...63 PART II Web Configurator...
Page 179: ...Chapter 21 Classifier OLT2406 User s Guide 179 Figure 112 Classifier Example...
Page 182: ...Chapter 22 Policy Rule OLT2406 User s Guide 182 Figure 113 Advanced Application Policy Rule...
Page 186: ...Chapter 22 Policy Rule OLT2406 User s Guide 186 Figure 114 Policy Example...
Page 248: ...Chapter 28 Loop Guard OLT2406 User s Guide 248 Figure 151 Advanced Application Loop Guard...
Page 393: ...393 PART III CLI Commands...
Page 581: ...Chapter 78 VoIP OLT2406 User s Guide 581...
Page 725: ...725 PART IV Troubleshooting Specifications Appendices and Index...