
30
You can enable or disable forwarding of unknown frames after the MAC learning limit is reached.
To enable the device to forward unknown frames after the MAC learning limit is reached:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter interface view.
•
Enter Layer 2 Ethernet interface
view.
interface
interface-type
interface-number
•
Enter Layer 2 aggregate
interface view.
interface bridge-aggregation
interface-number
N/A
3.
Configure the device to
forward unknown frames
received on the interface after
the MAC learning limit on the
interface is reached.
mac-address max-mac-count
enable-forwarding
By default, the device can forward
unknown frames received on an
interface after the MAC learning
limit on the interface is reached.
Assigning MAC learning priority to an interface
The MAC learning priority mechanism assigns either low priority or high priority to an interface. An
interface with high priority can learn MAC addresses as usual. However, an interface with low priority
is not allowed to learn MAC addresses already learned on a high-priority interface.
The MAC learning priority mechanism can help defend your network against MAC address spoofing
attacks. In a network that performs MAC-based forwarding, an upper layer device MAC address might
be learned by a downlink interface because of a loop or attack to the downlink interface. To avoid this
problem, perform the following tasks:
•
Assign high MAC learning priority to an uplink interface.
•
Assign low MAC learning priority to a downlink interface.
To make this feature take effect on an IRF fabric, you must also execute the
mac-address mac-roaming
enable
command to enable the MAC address synchronization feature on the IRF fabric.
To assign MAC learning priority to an interface:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter interface view.
•
Enter Layer 2 Ethernet interface
view:
interface
interface-type
interface-number
•
Enter Layer 2 aggregate interface
view:
interface bridge-aggregation
interface-number
N/A
3.
Assign MAC learning priority
to the interface.
mac-address mac-learning priority
{
high
|
low
}
By default, low MAC learning
priority is used.