Security
ExtremeWare XOS 11.3 Concepts Guide
318
NOTE
Blackhole FDB entries added due to MAC security violations on the BlackDiamond 8800 family of switches and the
Summit X450 switch are removed after each FDB aging period regardless of whether the MAC addresses in question
are still sending traffic. If the MAC addresses are still sending traffic, the blackhole entries will be re-added after
they have been deleted.
Locked entries do not get aged, but can be deleted like a regular permanent entry.
For ports that have lock-down in effect, the following traffic still flows to the port:
●
Packets destined for the permanent MAC and other non-blackholed MAC addresses
●
Broadcast traffic
●
EDP traffic
Traffic from the permanent MAC still flows from the virtual port.
To remove MAC address lock down, use the
unlock-learning
option from the following command:
configure ports <portlist> vlan <vlan name> [limit-learning <number> | lock-learning |
unlimited-learning | unlock-learning]
When you remove the lock down using the unlock-learning option, the learning-limit is reset to
unlimited, and all associated entries in the FDB are flushed.
DHCP Server
Dynamic Host Configuration Protocol (DHCP) support was introduced into ExtremeWare XOS in
release 11.0. In simple terms, a DHCP server dynamically manages and allocates IP addresses to clients.
When a client accesses the network, the DHCP server provides an IP address to that client. The client is
not required to receive the same IP address each time it accesses the network. A DHCP server with
limited configuration capabilities is included in the switch to provide IP addresses to clients.
This section describes the following topics:
●
Enabling and Disabling DHCP on page 318
●
Configuring the DHCP Server on page 319
●
Displaying DHCP Information on page 319
Enabling and Disabling DHCP
DHCP is enabled on a per port, per VLAN basis. To enable or disable DHCP on a port in a VLAN, use
one of the following commands:
enable dhcp ports <portlist> vlan <vlan_name>
disable dhcp ports <portlist> vlan <vlan name>
Содержание ExtremeWare XOS 11.3
Страница 20: ...Contents ExtremeWare XOS 11 3 Concepts Guide 20...
Страница 25: ...1 Using ExtremeWare XOS...
Страница 26: ......
Страница 38: ...ExtremeWare XOS Overview ExtremeWare XOS 11 3 Concepts Guide 38...
Страница 58: ...Accessing the Switch ExtremeWare XOS 11 3 Concepts Guide 58...
Страница 146: ...Configuring Slots and Ports on a Switch ExtremeWare XOS 11 3 Concepts Guide 146...
Страница 218: ...Status Monitoring and Statistics ExtremeWare XOS 11 3 Concepts Guide 218...
Страница 240: ...Virtual LANs ExtremeWare XOS 11 3 Concepts Guide 240...
Страница 248: ...Virtual Routers ExtremeWare XOS 11 3 Concepts Guide 248...
Страница 278: ...Access Lists ACLs ExtremeWare XOS 11 3 Concepts Guide 278...
Страница 288: ...Routing Policies ExtremeWare XOS 11 3 Concepts Guide 288 entry deny_rest if then deny...
Страница 344: ...Security ExtremeWare XOS 11 3 Concepts Guide 344...
Страница 393: ...2 Using Switching and Routing Protocols...
Страница 394: ......
Страница 454: ...Spanning Tree Protocol ExtremeWare XOS 11 3 Concepts Guide 454...
Страница 484: ...Extreme Standby Router Protocol ExtremeWare XOS 11 3 Concepts Guide 484...
Страница 514: ...IPv4 Unicast Routing ExtremeWare XOS 11 3 Concepts Guide 514...
Страница 530: ...IPv6 Unicast Routing ExtremeWare XOS 11 3 Concepts Guide 530...
Страница 538: ...RIP ExtremeWare XOS 11 3 Concepts Guide 538...
Страница 556: ...OSPF ExtremeWare XOS 11 3 Concepts Guide 556...
Страница 566: ...OSPFv3 ExtremeWare XOS 11 3 Concepts Guide 566...
Страница 589: ...3 Appendixes...
Страница 590: ......
Страница 640: ...CNA Agent ExtremeWare XOS 11 3 Concepts Guide 640...
Страница 670: ...Glossary ExtremeWare XOS 11 3 Concepts Guide 670...
Страница 698: ...Index ExtremeWare XOS 11 3 Concepts Guide 698...