Mff Working Mechanism; Protocols And Standards; Configuring Mff; Enabling Mff - HPE FlexNetwork 7500 Series Security Configuration Manual

Table of Contents

Advertisement

Automatic mode
The automatic mode applies to networks that allocate IP addresses to hosts through DHCP.
In automatic mode, the device configured with DHCP snooping resolves Option 3 (Router IP option)
in the received DHCP ACK message to obtain a gateway for the DHCP snooping entry. If the DHCP
ACK message contains multiple gateway addresses, only the first one is recorded for the entry. If the
message contains no gateway IP address, the first gateway recorded by the current VLAN is used.
If the sender MAC address of an ARP packet from a gateway is different from the MAC address
recorded for the gateway, the MFF device updates the gateway's MAC address.
NOTE:
In MFF automatic mode, a VLAN can learn and maintain a maximum of 20 gateways. The gateway
IP addresses will not be updated, and the gateway information does not age out unless MFF is
disabled.

MFF working mechanism

An MFF-enabled device implements Layer 3 communication between hosts by intercepting ARP
requests from the hosts and replies with the MAC address of a gateway. This mechanism helps
reduce the number of broadcast messages.
The MFF device processes ARP packets as follows:
After receiving an ARP request from a host, the MFF device sends the MAC address of the
corresponding gateway to the host. In this way, hosts in the network have to communicate at
Layer 3 through a gateway.
After receiving an ARP request from a gateway, the MFF device sends the requested host's
MAC address to the gateway if the corresponding entry is available. If the entry is not available,
the MFF device forwards the ARP request.
The MFF device forwards ARP replies between hosts and gateways.
If the source MAC addresses of ARP requests from gateways are different from those recorded,
the MFF device updates and broadcasts the IP and MAC addresses of the gateways.

Protocols and standards

RFC 4562, MAC-Forced Forwarding

Configuring MFF

Enabling MFF

For MFF to take effect in manual mode, make sure ARP snooping is enabled on the device.
For MFF to take effect in automatic mode, make sure DHCP snooping is enabled on the device and
DHCP snooping trusted ports are configured.
To enable MFF and specify an MFF operating mode:
Step
1.
Enter system view.
2.
Enter VLAN view.
3.
Enable MFF.
Command
system-view
vlan vlan-id
Enable automatic mode:
457
Remarks
N/A
N/A
By default, MFF is disabled.

Advertisement

Table of Contents
loading

Table of Contents