1.6.1.1 Configuring a Static MAC Address Entry
Context
To ensure communication security, you can configure MAC addresses of trusted upstream
devices or users as static MAC address entries. When there are few trusted users, configure static
MAC address entries to ensure security. When there are many trusted users, configure dynamic
binding according to
1.7.2 Example for Configuring Port Security
Procedure
Step 1
Run:
system-view
The system view is displayed.
Step 2
Run:
mac-address
static
mac-address
interface-type interface-number
vlan
vlan-id
A static MAC address entry is configured.
NOTE
A static MAC address entry takes precedence over a dynamic MAC address entry. The system discards packets
with configured static MAC addresses that have been learned by other interfaces.
----End
1.6.1.2 Configuring a Blackhole MAC Address Entry
Context
To save the MAC address table space, protect user devices or network devices from MAC
address attacks, you can configure untrusted MAC addresses as blackhole MAC addresses.
Packets with source or destination MAC addresses matching the blackhole MAC address entries
are discarded.
Procedure
Step 1
Run:
system-view
The system view is displayed.
Step 2
Run:
mac-address
blackhole
mac-address
vlan
vlan-id
A blackhole MAC address entry is configured.
----End
Huawei AR530&AR550 Series Industrial Switch Routers
Configuration Guide - Ethernet Switching
1 MAC Address Table Configuration
Issue 01 (2014-11-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
10