Anti-Spoofing Control Types And Traffic Exemptions; Per-Service Anti-Spoofing - Alcatel-Lucent 7302 Information Manual

Intelligent services access manager
Table of Contents

Advertisement

Source address
anti-spoofing mode
Static
Dynamic
The anti-spoofing control type limits the number of authorized source address
entries.
When static or dynamic source address anti-spoofing is enabled, the LT card
downloads the static entries provisioned for an ONT UNI port to the ONT by way of
OMCI. When a static entry is removed or anti-spoofing is disabled, the LT card
notifies the ONT to remove the corresponding anti-spoofing filter(s).
When dynamic anti-spoofing is enabled, the LT card forwards the currently leased
IP addresses to the ONT by way of OMCI after an IP address is leased, or a DHCP
lease expires or is released. When a UNI port has reached its maximum allowed
number of IP source addresses, the LT card drops any subsequent DHCP ACKs with
a leased IP address that is not in the lease table. IP source addresses that are added
dynamically through DHCP survive ONT restarts, LT restarts, and NT switchovers.
See the appropriate P-OLT TL1 documentation for configuration information.

Per-service anti-spoofing

Per service dynamic or static IP anti-spoofing configuration using TL1 via the
P-OLT is supported. The dynamic IP anti-spoofing allows up to eight IP addresses
to be learned. The static IP anti-spoofing allows up to eight IP addresses to be
specified by the operator.
When services dynamic IP-only anti-spoofing is configured for the ONT UNI, and
per service anti-spoofing is enabled for a service, packets are allowed with a
combination of leased IP address and the C-VLAN ID of the service. A packet sent
upstream (user to network) over the service is permitted if the incoming packet's
source IP address is that of the IP address leased for that service. In the case of static
IP addresses (configured IP addresses), the C-VLAN check is not performed for the
service in the ONT UNI and hence filtering is based on static IP address.
Alcatel-Lucent 7302 ISAM | 7330 ISAM FTTN | 7360 ISAM FX ONT R04.06.02
3FE 55873 AAAA TCZZA
Edition 01
ONT Product Information Guide
Table 1-13 Anti-spoofing control types and traffic exemptions
Anti-spoofing control type
MAC-only anti-spoofing
IP-only anti-spoofing
MAC and IP anti-spoofing
IP-only anti-spoofing
1 — ONT and MDU overview
Traffic exemptions
Is applied to all data traffic
Is not applied to non-IP traffic,
such as:
PPPoE
ARP
EAPOL, EAP
Is not applied to DHCP packets to
allow a subscriber to obtain a
DHCP lease.
November 2013
1-31

Advertisement

Table of Contents
loading

This manual is also suitable for:

73607330

Table of Contents