Mff Work Flow; Protocols And Standards; Configuring Mff - HP 10500 Series Configuration Manual

Security configuration guide
Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

entry. If the DHCP ACK message contains multiple gateway addresses, only the first one is recorded for
the entry. If the message contains no gateway IP address, the first gateway recorded by the current VLAN
is used.
In MFF automatic mode, a VLAN can learn and maintain up to 20 gateways. The gateway IP addresses
will not be updated, and the gateway information does not age out unless MFF is disabled.
If the source MAC address of an incoming ARP packet from a gateway is different from that of the
gateway, the MFF device uses the new MAC to replace the old one.

MFF work flow

Hosts connecting to an MFF device use the ARP fast-reply mechanism for Layer 3 communication. This
mechanism helps reduce the number of broadcast messages.
The MFF device processes ARP packets as follows:
After receiving an ARP request from a host, the MFF device sends the MAC address of the
corresponding gateway to the host. In this way, hosts in the network have to communicate at Layer
3 through a gateway.
After receiving an ARP request from a gateway, the MFF device sends the requested host's MAC
address to the gateway if the corresponding entry is available. If the entry is not available, the MFF
device forwards the ARP request.
The MFF device forwards ARP replies between hosts and gateways.
If the source MAC addresses of ARP requests from gateways are different from those recorded, the
MFF device updates and broadcasts the IP and MAC addresses of the gateways.

Protocols and standards

RFC 4562, MAC-Forced Forwarding

Configuring MFF

Prerequisites
In MFF automatic mode, enable DHCP snooping on the device and configure DHCP snooping
trusted ports.
In MFF manual mode, enable ARP snooping on the device.
Enabling MFF and specifying an MFF operating mode
Step
1.
Enter system view.
2.
Enter VLAN view.
3.
Enable MFF and specify an
MFF operating mode.
Configuring a network port
To configure the port as a network port:
Command
system-view
vlan vlan-id
mac-forced-forwarding { auto |
default-gateway gateway-ip }
275
Remarks
N/A
N/A
Disabled by default.

Advertisement

Table of Contents
loading

Table of Contents