Assigning Mac Learning Priority To An Interface - HP 6125XLG Configuration Manual

Blade switch layer 2 lan switching
Table of Contents

Advertisement

To enable the interface to forward frames with unknown source MAC addresses after the upper limit is
reached:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Enable the device to forward
frames with unknown source
MAC addresses after the
upper limit on the interface is
reached.

Assigning MAC learning priority to an interface

All networks that perform MAC-based forwarding are facing MAC address spoofing attacks. For
example, an upper layer device MAC address might be learned by a downlink interface because of a
loop or attack to the downlink interface.
The MAC learning priority mechanism assigns either low priority or high priority to an interface. An
interface with high MAC learning priority can learn MAC addresses as usual. However, an interface with
low MAC learning priority is not allowed to learn MAC addresses already learned on a high-priority
interface.
The MAC learning priority mechanism can help defend your network against MAC address spoofing
attacks. Assign an uplink interface high MAC learning priority, and a downlink interface low MAC
learning priority. This will prevent the downlink interface from learning the MAC address of an upper
layer device.
To make this feature take effect on an IRF fabric, you must also execute the mac-address mac-roaming
enable command to enable the MAC address synchronization feature on the IRF fabric.
To assign MAC learning priority to an interface:
Step
1.
Enter system view.
2.
Enter interface view.
Command
system-view
Enter Layer 2 Ethernet interface
view.
interface interface-type
interface-number
Enter Layer 2 aggregate
interface view.
interface bridge-aggregation
interface-number
mac-address max-mac-count
enable-forwarding
Command
system-view
Enter Layer 2 Ethernet interface
view:
interface interface-type
interface-number
Enter Layer 2 aggregate interface
view:
interface bridge-aggregation
interface-number
26
Remarks
N/A
N/A
By default, the interface forwards
frames with unknown source MAC
addresses after the upper limit is
reached.
Remarks
N/A
N/A

Advertisement

Table of Contents
loading

Table of Contents