Operation Manual – MAC Address Table Management
H3C S3100 Series Ethernet Switches
Chapter 1
MAC Address Table
Management
1-9
You can disable a switch from learning MAC addresses in specific VLANs to improve
stability and security for the users belong to these VLANs and prevent unauthorized
accesses.
Table 1-2
Disable MAC address learning for a VLAN
Operation
Command
Description
Enter system view
system-view
—
Enter VLAN view
vlan
vlan-id
—
Disable the switch from
learning MAC
addresses in the VLAN
mac-address
max-mac-count
0
Required
By default, a switch learns
MAC addresses in any VLAN.
Note:
z
If the VLAN is configured as a remote probe VLAN used by port mirroring, you can
not disable MAC address learning of this VLAN. Similarly, after you disable MAC
address learning, this VLAN can not be configured as a remote probe VLAN.
z
Disabling the MAC address learning function of a VLAN takes no effect on enabling
the MAC address authentication on the ports that belong to the VLAN.
1.2.6 Assigning MAC Addresses for Ethernet Ports
By default, no Ethernet port of an S3100 switch is configured with a MAC address.
Therefore, when the switch sends Layer 2 protocol packets, for example, BPDUs of
STP, it uses the MAC address predefined in the protocol as the source address to send
the BPDUs. As switches in your network may use the same source MAC address for
Layer 2 protocol data units (PDUs), different ports on a switch may learn the same MAC
address, thus affecting the maintenance of the MAC address table.
To avoid the problem, you are allowed to assign MAC addresses to the Ethernet ports
on an S3100 series switch. The idea is to assign a MAC address (called the start port
MAC address) for the start Ethernet port, that is, Ethernet 1/0/1, and each of the
following ports uses the MAC address of the preceding port plus 1 as its MAC address.
For example, if you configure 000f-e200-0001 as the start port MAC address, then port
Ethernet 1/0/2 will take MAC address 000f-e200-0002, and so on.