8
To configure the device to forward unknown frames received on the interface after the MAC learning
limit on the interface is reached:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter interface view.
•
Enter Layer 2 Ethernet
interface view.
interface
interface-type
interface-number
•
Enter Layer 2 aggregate
interface view.
interface
bridge-aggregation
interface-number
N/A
3.
Configure the device to
forward unknown frames
received on the interface
after the MAC learning limit
on the interface is reached.
mac-address max-mac-count
enable-forwarding
By default, the device can forward
unknown frames received on an
interface after the MAC learning
limit on the interface is reached.
You can use the
undo
mac-address max-mac-count
enable-forwarding
command in
Layer 2 aggregate interfaces.
Assigning MAC learning priority to interfaces
The MAC learning priority mechanism assigns either low priority or high priority to an interface. An
interface with high priority can learn MAC addresses as usual. However, an interface with low priority
is not allowed to learn MAC addresses already learned on a high-priority interface.
The MAC learning priority mechanism can help defend your network against MAC address spoofing
attacks. In a network that performs MAC-based forwarding, an upper layer device MAC address
might be learned by a downlink interface because of a loop or attack to the downlink interface. To
avoid this problem, perform the following tasks:
•
Assign high MAC learning priority to an uplink interface.
•
Assign low MAC learning priority to a downlink interface.
To assign MAC learning priority to an interface:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
Содержание H3C S7500E-X
Страница 70: ...57 ...