Chapter 14 Access Security Configuration
4.
(Optional) Query the configuration of MAC address anti-spoofing.
ZXAN(config)#show security mac-anti-spoofing configuration
mac-move-report :enable
mac-move-report interval:30[minutes]
mac-anti-spoofing :enable
uplink-protect
:disable
5.
(Optional) Query the MAC move log.
ZXAN#show security mac-move-log
Flag *--macMove is forbidden by system.
the total mac-move-log num:2
-------------------------------------------------------------------------
mac-address
vlan
cfgMacProtect
moveToPort
moveToIfId
moveCount
index trapFlag detector queryPort
moveFromPort
moveFromIfId trapCount
-------------------------------------------------------------------------
0002.0304.0506 100
UNNEED
inner-port_1/12/1
unknown(0)
1
1
SENDED
MP
UNNEED
inner-port_1/5/1
unknown(0)
1
-------------------------------------------------------------------------
0002.0304.0507 100
UNNEED
inner-port_1/12/2
unknown(0)
1
2
*SENDED
MP
UNNEED
inner-port_1/5/1
unknown(0)
1
– End of Steps –
14.2.2 Configuring the Service Gateway MAC Anti-Spoofing
Service gateway MAC address anti-spoofing prevents malicious MAC address spoofing
between user ports and permits MAC address learning between uplink ports.
Context
The ZXA10 C300 supports the following features by service gateway MAC anti-spoofing:
l
A MAC address learnt by a user port can be learnt by an uplink port as well.
l
The same MAC address cannot be learnt by two user ports.
l
The same MAC address can be learnt by multiple uplink ports.
Steps
1.
Enable global MAC address anti-spoofing function.
ZXAN(config)#security mac-anti-spoofing enable
2.
Enable MAC address anti-spoofing function with uplink protection.
ZXAN(config)#security mac-anti-spoofing uplink-protect enable
3.
(Optional) Query the configuration of MAC address anti-spoofing.
ZXAN(config)#show security mac-anti-spoofing configuration
14-9
SJ-20130520164529-007|2013-06-30 (R1.0)
ZTE Proprietary and Confidential
Содержание ZXA10 C300
Страница 8: ...VI SJ 20130520164529 007 2013 06 30 R1 0 ZTE Proprietary and Confidential ...
Страница 294: ...Tables This page intentionally left blank VI SJ 20130520164529 007 2013 06 30 R1 0 ZTE Proprietary and Confidential ...
Страница 301: ...Glossary VoIP Voice over Internet Protocol XIII SJ 20130520164529 007 2013 06 30 R1 0 ZTE Proprietary and Confidential ...