l
The index of the service port is 1.
l
The static MAC address of this service port is 1010-1010-1010.
l
The maximum number of learnable MAC addresses of this service port is 0.
To bind MAC address 1010-1010-1010 to service port 1 so that service port 1 allows only the
packets with source MAC address 1010-1010-1010 to pass, do as follows:
huawei(config)#
mac-address static service-port 1 1010-1010-1010
huawei(config)#
mac-address max-mac-count service-port 1 0
To enable anti-MAC address spoofing in VLAN 10 and set the maximum number of learnable
MAC addresses of service port 2 in this VLAN to 7, do as follow:
huawei(config)#
security anti-macspoofing enable
huawei(config)#
vlan service-profile profile-id 3
huawei(config-vlan-srvprof-3)#
security anti-macspoofing enable
Info: Please use the commit command to make modifications take
effect
huawei(config-vlan-srvprof-3)#
commit
huawei(config-vlan-srvprof-3)#
quit
huawei(config)#
vlan bind service-profile 10 profile-id 3
huawei(config)#
security anti-macspoofing max-mac-count service-port 2 7
3.11 Configuring System Security
This topic describes how to configure the network security and protection measures of the system
to protect the system from malicious attacks.
Context
With the system security feature, the MA5616 can be protected against the attacks from the
network side or user side, and therefore the MA5616 can run stably in the network.
l
ACL/Packet filtering firewall
l
Blacklist
l
Anti-DoS attack
l
MAC address filtering
l
User-side ring network detection
l
Allowed/Denied address segment
lists the default settings of system security.
Table 3-16
Default settings of system security
Parameter
Default Setting
Firewall blacklist
Disabled
Anti-DoS attack
Disabled
User-side ring network detection
Disabled
SmartAX MA5616 Multi-service Access Module
Configuration Guide
3 Basic Configuration
Issue 04 (2011-10-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
88