Port Security; Chapter 70 Port Security; Port Security Overview; Port Security Commands - ZyXEL Communications OLT2406 User Manual

2u temperature-hardened, 6-slot mini chassis gpon olt
Table of Contents

Advertisement

70.1 Port Security Overview

Port security allows only packets with dynamically learned MAC addresses and/or configured static
MAC addresses to pass through a port on the OLT. The OLT can learn up to 32K MAC addresses in total
with no limit on individual ports other than the sum cannot exceed 32K.
For maximum port security, enable this feature, disable MAC address learning and configure static MAC
address(es) for a port. It is not recommended you disable port security together with MAC address
learning as this will result in many broadcasts. By default, MAC address learning is still enabled even
though port security is not activated.
With port-security enabled on the OLT, each subscriber port counts the number of newly learnt MAC
addresses. Configure the number of MAC addresses a specific port can learn and the OLT drops Source
Lookup Failure (SLF) packets on the port that exceed the limit.
Anti-MAC spoofing lets you set whether or not to allow a subscriber device to move between OLT
subscriber ports. This means the OLT has learned a subscriber device's source MAC address at one port
but receives packets containing the same source MAC address through another subscriber port before
the learned MAC address times out from the MAC address table. Disable anti-MAC spoofing to have
the OLT allow the port move and learn the source MAC address on the new port. Enable anti-MAC
spoofing to have the OLT drop the packets and not learn the source MAC address on the new port.
Anti-MAC spoofing applies to the subscriber ports, not the uplink ports.

70.2 Port Security Commands

The following table lists the port security commands.
Table 255 Port Security Commands
COMMAND
port-security
port-security <aid>
no port-security
no port-security <aid>
C

Port Security

DESCRIPTION
Enables the port security feature.
Enables port security on the specified port.
aid: <msc|ge|pon>-<slot>-<port>
Disables the port security feature.
Disables port security on the specified port.
aid: <msc|ge|pon>-<slot>-<port>
OLT2406 User's Guide
504
H A P T E R
70
M
P
C
13
C
13
C
13
C
13

Advertisement

Table of Contents
loading

Table of Contents