Alcatel-Lucent 7750 SR OS Service Manual page 1009

Service router - mobile gateway
Hide thumbs Also See for 7750 SR OS:
Table of Contents

Advertisement

Interface Anti-Spoofing Commands
anti-spoof
Syntax
anti-spoof {ip | mac | ip-mac}
no anti-spoof-type
Context
config>service>vprn>if>sap
config>service>vprn>sub-if>grp-if>sap
Description
This command enables anti-spoof filtering and optionally changes the anti-spoof matching type for
the interface.
The type of anti-spoof filtering defines what information in the incoming packet is used to generate
the criteria to lookup an entry in the anti-spoof filter table. The type parameter (ip, mac, ip-mac) is
defines the anti-spoof filter type enforced by the SAP when anti-spoof filtering is enabled.
The no form of the command disables anti-spoof filtering on the SAP.
Default
Filter type default types:
Parameters
ip — Configures SAP anti-spoof filtering to use only the source IP address in its lookup. If a static
mac — Configures SAP anti-spoof filtering to use only the source MAC address in its lookup.
ip-mac — Configures SAP anti-spoof filtering to use both the source IP address and the source MAC
arp-populate
Syntax
[no] arp-populate
Context
config>service>vprn>if
config>service>vprn>sub-if>subscriber-interface
config>service>vprn>sub-if>grp-if
Description
This command enables populating static and dynamic hosts into the system ARP cache. When
enabled, the host's IP address and MAC address are placed in the system ARP cache as a managed
7750 SR OS Services Guide
• Non-Ethernet encapsulation default anti-spoof filter type — When enabled on a non-Ethernet
encapsulated SAP, the anti-spoof filter default type is ip.
• Ethernet encapsulated default anti-spoof filter type — When enabled on an Ethernet encapsu-
lated SAP, the anti-spoof default type is ip-mac.
• Default anti-spoof filter state — Anti-spoof filtering is disabled by default on the SAP.
host exists on the SAP without an IP address specified, the anti-spoof type ip command will fail.
Setting the anti-spoof filter type to mac is not allowed on non-Ethernet encapsulated SAPs. If a
static host exists on the SAP without a specified MAC address, the anti-spoof type mac
command will fail. The anti-spoof type mac command will also fail if the SAP does not support
Ethernet encapsulation.
address in its lookup. If a static host exists on the SAP without both the IP address and MAC
address specified, the anti-spoof type ip-mac command will fail. This is also true if the default
anti-spoof filter type of the SAP is ip-mac and the default is not overridden. The anti-spoof type
ip-mac command will also fail if the SAP does not support Ethernet encapsulation.
Virtual Private Routed Network Services
Page 1009

Advertisement

Table of Contents
loading

Table of Contents