MAC Address Security
ExtremeWare XOS 11.3 Concepts Guide
315
mode. Although SNMP, Telnet, and switch ports are enabled by default, the script prompts you to
confirm those settings. By answering
N (No)
to each question, you keep the default settings.
Would you like to disable Telnet? [y/N]: No
Would you like to disable SNMP [y/N]: No
Would you like unconfigured ports to be turned off by default [y/N]: No
In addition, if you keep the default settings for SNMP and Telnet, the switch returns the following
interactive script:
Since you have chosen less secure management methods, please remember to increase
the security of your network by taking the following actions:
* change your admin password
* change your SNMP public and private strings
* consider using SNMPv3 to secure network management traffic
For more detailed information about safe defaults mode, see
“Safe Defaults Setup Method” on page 47
.
MAC Address Security
The switch maintains a database of all media access control (MAC) addresses received on all of its ports.
The switch uses the information in this database to decide whether a frame should be forwarded or
filtered. MAC address security allows you to control the way the Forwarding Database (FDB) is learned
and populated. For more information about the FDB, see
Chapter 11
, “
Forwarding Database
.”
The following section
“Limiting Dynamic MAC Addresses”
describes how MAC address security
allows you to limit the number of dynamically-learned MAC addresses allowed per virtual port. The
section
“MAC Address Lock Down” on page 317
describes how you can also “lock” the FDB entries for
a virtual port, so that the current entries will not change, and no additional addresses can be learned on
the port.
NOTE
You can either limit dynamic MAC FDB entries or lock down the current MAC FDB entries, but not both.
Using ACLS, you can also prioritize or stop packet flows based on the source MAC address of the
ingress virtual LAN (VLAN) or the destination MAC address of the egress VLAN. For more information
about ACL policies, see
Chapter 13
, “
Access Lists (ACLs)
.”
Another method of enhancing security, depending on your network configuration, is to disable Layer 2
flooding. For more information about enabling and disabling Layer 2 flooding, see the section,
“
Disabling Egress Flooding
” in
Chapter 11
, “
Forwarding Database
.”
Limiting Dynamic MAC Addresses
You can set a predefined limit on the number of dynamic MAC addresses that can participate in the
network. After the FDB reaches the MAC limit, all new source MAC addresses are blackholed at both
the ingress and egress points. These dynamic blackhole entries prevent the MAC addresses from
learning and responding to Internet Control Message Protocol (ICMP) and address resolution protocol
(ARP) packets.
Содержание ExtremeWare XOS 11.3
Страница 20: ...Contents ExtremeWare XOS 11 3 Concepts Guide 20...
Страница 25: ...1 Using ExtremeWare XOS...
Страница 26: ......
Страница 38: ...ExtremeWare XOS Overview ExtremeWare XOS 11 3 Concepts Guide 38...
Страница 58: ...Accessing the Switch ExtremeWare XOS 11 3 Concepts Guide 58...
Страница 146: ...Configuring Slots and Ports on a Switch ExtremeWare XOS 11 3 Concepts Guide 146...
Страница 218: ...Status Monitoring and Statistics ExtremeWare XOS 11 3 Concepts Guide 218...
Страница 240: ...Virtual LANs ExtremeWare XOS 11 3 Concepts Guide 240...
Страница 248: ...Virtual Routers ExtremeWare XOS 11 3 Concepts Guide 248...
Страница 278: ...Access Lists ACLs ExtremeWare XOS 11 3 Concepts Guide 278...
Страница 288: ...Routing Policies ExtremeWare XOS 11 3 Concepts Guide 288 entry deny_rest if then deny...
Страница 344: ...Security ExtremeWare XOS 11 3 Concepts Guide 344...
Страница 393: ...2 Using Switching and Routing Protocols...
Страница 394: ......
Страница 454: ...Spanning Tree Protocol ExtremeWare XOS 11 3 Concepts Guide 454...
Страница 484: ...Extreme Standby Router Protocol ExtremeWare XOS 11 3 Concepts Guide 484...
Страница 514: ...IPv4 Unicast Routing ExtremeWare XOS 11 3 Concepts Guide 514...
Страница 530: ...IPv6 Unicast Routing ExtremeWare XOS 11 3 Concepts Guide 530...
Страница 538: ...RIP ExtremeWare XOS 11 3 Concepts Guide 538...
Страница 556: ...OSPF ExtremeWare XOS 11 3 Concepts Guide 556...
Страница 566: ...OSPFv3 ExtremeWare XOS 11 3 Concepts Guide 566...
Страница 589: ...3 Appendixes...
Страница 590: ......
Страница 640: ...CNA Agent ExtremeWare XOS 11 3 Concepts Guide 640...
Страница 670: ...Glossary ExtremeWare XOS 11 3 Concepts Guide 670...
Страница 698: ...Index ExtremeWare XOS 11 3 Concepts Guide 698...