144
Proprietary Information: Not for use or disclosure except by written agreement with Calix.
© Calix. All Rights Reserved.
Parameter
Description
Valid Options
Source MAC Limit
Number of unique MAC addresses allowed on a subscriber port.
Note:
A limit of 0 means “do not enforce a limit” (that is, unlimited).
0 ‡-255
Source MAC Age (s)
Maximum age for source MAC addresses, in seconds.
60-86400
300 ‡
DHCP Lease Limit
Specifies the maximum number of DHCP leases allowed on the
xDSL port (aggregate for all services). Only VLANs with DHCP
Snooping on the port are subject to the DHCP lease limit. In the
VDSL2 and GPON subsystems, DHCP leases cannot be learned
without also applying a limit to the number of learned leases on the
port. Each Ethernet port has an associated Port Security Profile that
can limit DHCP leases in a range of 1-16 and applies to IPv4 and
IPv6 addresses, independently. A security profile used by an xDSL
port must have a DHCP lease limit value of 10 or less. The E7 does
not support infinite lease times on DHCP snooping.
1-16
8 ‡
Upstream
Broadcast/Multicast
Limit (Kb/sec)
Specifies the maximum rate of Layer 2 broadcast traffic per second
allowed on the xDSL port.
0 – 10240 Kbps (10 Mbps)
24 ‡
L2CP Filter
Layer 2 Control Protocol filter sets whether to pass or discard the
L2CP protocol frames. Besides selecting from the system default
filters (all-discard or all-tunnel), you can create additional filters to
specify which L2CP ranges to discard or tunnel.
Note: For TLAN services, this parameter must be set to all-tunnel.
all-discard ‡
all-tunnel, or any previously-
created filter
DOS Attack Detection
Whether to enable or disable Denial Of Service (DOS) attack
detection against PPPoE control flows. DOS attack is implemented
for PPPoE discovery phase packets only, where it meters the arrival
of PPPoE control packets from a particular subscriber, and uses that
rate to detect an arrival rate being above a threshold for a time. When
the threshold is detected, the condition is considered "yellow". When
the threshold continues for a specified time, the condition is
considered "red" and a DOS attack condition exists. Counters are
kept for packets arriving in the "yellow" and "red" conditions.
Threshold rates:
Yellow - 10 pkts/second
Red - 10 pkts/second for 5 consecutive seconds
When the Red condition occurs, the interface is disabled for 300
seconds.
selected = enabled ‡
unselected = disabled
Allow IPv6
IPv6 traffic flows by default. If the setting in this profile is changed to
"Disabled", IPv6 unicast, multicast and broadcast traffic ingressing
the xDSL interface is blocked.
selected = enabled ‡
unselected = disabled
802.1x Profile
Specifies the previously created 802.1x profile to apply to the security
profile.
1-10
*Required field
‡ Default
To create a Ethernet security profile
1.
On the Navigation Tree, click the unit.
2.
Click
Profiles
>
Security > Ethernet > Profiles.
3.
In the menu, click
Create
to open the Create Security Profile dialog box.
4.
Configure the Ethernet Security Profile, as described in the table above.
5.
Apply the Ethernet Security Profile to an xDSL port associated interface by selecting the
profile by name under the
Security Profile
option.