To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter Layer 2 Ethernet
interface view
interface
interface-type
interface-number
Enter Layer 2
Ethernet
interface view
or port group
view
Enter port group view
port-group manual
port-group-name
Use either command.
The configuration made in Layer 2
Ethernet interface view takes effect
on the current interface only. The
configuration made in port group
view takes effect on all the member
ports in the port group.
Configure the MAC learning limit on the
interface or port group
mac-address
max-mac-count
count
Required
No MAC learning limit is
configured by default.
NOTE:
•
Layer 2 aggregate interfaces do not support the
mac-address max-mac-count
command.
•
Do not configure the MAC learning limit on any member ports of an aggregation group. Otherwise, the
member ports cannot be selected.
Displaying and maintaining MAC address tables
To do…
Use the command…
Remarks
Display MAC address table
information
display mac-address
[
mac
-
address
[
vlan
vlan-id
] |
[ [
dynamic
|
static
] [
interface
interface-type
interface-number
] |
blackhole
] [
vlan
vlan-id
]
[
count
] ] [
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
Display the aging timer for
dynamic MAC address entries
display mac-address aging-time
[
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
Display the system or interface
MAC address learning state
display mac-address mac-learning
[
interface
-
type
interface
-
number
] [
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
Display MAC address
statistics
display mac-address statistics
[
|
{
begin
|
exclude
|
include
}
regular-expression
]
Available in any view
MAC address table configuration example
Network requirements
•
The MAC address of one host is 000f-e235-dc71 and belongs to VLAN 1. It is connected to Ethernet
1/0/1 of the device. To prevent MAC address spoofing, add a static entry into the MAC address
table of the device for the host.
•
The MAC address of another host is 000f-e235-abcd and belongs to VLAN 1. Because this host
once behaved suspiciously on the network, you can add a blackhole MAC address entry for the
MAC address to drop all packets destined for the host.
•
Set the aging timer for dynamic MAC address entries to 500 seconds.
21