EVCs on Port Channels
An EtherChannel bundles individual Ethernet links into a single logical link that provides the aggregate
bandwidth of up to eight physical links. The Ethernet Virtual Connection Services (EVCS) EtherChannel
feature provides support for EtherChannels on service instances.
The MAC Address Security on EVC Port Channel services is supported only on bridge domains over
Ethernet and is not supported on xconnect services.
Note
EVCS uses the concepts of EVCs and service instances.
Load balancing is done on an Ethernet flow point (EFP) basis where a number of EFPs exclusively pass traffic
through member links.
MAC Security and MAC Addressing
MAC security is enabled on a service instance by configuring the
mac security
command. Various MAC
security elements can be configured or removed regardless of whether the
mac security
command is presently
configured, but these configurations become operational only when the
mac security
command is applied.
In this document, the term
“
secured service instance
”
is used to describe a service instance on which MAC
security is configured. The MAC addresses on a service instance on which MAC security is configured are
referred to as
“
secured MAC addresses.
”
Secured MAC addresses can be either statically configured (as a
permit list) or dynamically learned.
MAC Address Permit List
A permit list is a set of MAC addresses that are permitted on a service instance. Permitted addresses permanently
configured into the MAC address table of the service instance.
On a service instance that is a member of a bridge domain, the operator is permitted to configure one or more
permitted MAC addresses.
For each permitted address, eligibility tests are performed and after the address passes these tests, it is either:
•
Programmed into the MAC address table of the bridge domain, if MAC security is enabled on the service
instance or,
•
Stored in an area of memory referred to as
“
MAC table cache
”
if MAC security is not enabled on the
service instance. When MAC security is enabled, the addresses from the MAC table cache are added to
the MAC address table as secure addresses.
The eligibility tests performed when a user tries to add a MAC address to the permit list on a service instance
are as follows:
•
If the address is already a denied address on the service instance, the configuration is rejected with an
appropriate error message.
•
If the acceptance of this address would increase the secure address count on the service instance beyond
the maximum number allowed, an attempt is made to make room by removing an existing address from
Carrier Ethernet Configuration Guide (Cisco ASR 920 Series)
83
Configuring MAC Address Limiting on Service Instances Bridge Domains and EVC Port Channels
EVCs on Port Channels
Содержание ASR 920 series
Страница 2: ... 2014 Cisco Systems Inc All rights reserved ...
Страница 273: ...Carrier Ethernet Configuration Guide Cisco ASR 920 Series 255 Configuring Ethernet CFM Designing CFM Domains ...
Страница 302: ...Carrier Ethernet Configuration Guide Cisco ASR 920 Series 284 Configuring Ethernet CFM Glossary ...