System Security
Security
Vulnerability
Solution
Description and Usage
Suggestion
DoS attack
Enable the anti-DoS-attack
function for OLT and
MDU.
After the anti-DoS-attack function is
enabled, control packets are
monitored and those exceeding the
number threshold are discarded.
Use this solution for new site
deployment.
IP attack
Enable the anti-IP-attack
function for OLT and
MDU.
After the anti-IP-attack function is
enabled, a device discards the IP
packets received from the user side
whose destination IP address is the IP
address of the device, and therefore
the system is protected.
Use this solution for new site
deployment.
User Security
Security
Vulnerability
Solution
Description and Usage
Suggestion
MAC spoofing
Enable the anti-MAC-
duplicate function for OLT
and MDU.
After anti-MAC-duplicate is enabled,
the system records the first MAC
address learnt from the port and binds
the MAC address to the port and
VLAN. If receiving packets sent from
the host that has the same MAC
address with the port, the system
discards the packets directly. In this
case, it can prevent users from forging
MAC addresses to perform malicious
attacks.
Use this solution for new site
deployment.
MAC attack
Enable the anti-MAC
spoofing function for OLT
and MDU.
After anti-MAC spoofing is enabled,
the system can prevent users from
forging IP addresses to perform
malicious attacks.
Use this solution for new site
deployment.
SmartAX MA5600T/MA5603T/MA5608T Multi-service
Access Module
Commissioning and Configuration Guide
13 FTTO Configuration (Large-sized Enterprise Access)
Issue 01 (2014-04-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
1265