Optional) Configuring Mac Address Security On An Interface - Huawei Quidway S3700 Series Configuration Manual

Hide thumbs Also See for Quidway S3700 Series:
Table of Contents

Advertisement

Quidway S3700 Series Ethernet Switches
Configuration Guide - Security
Or, run:
vlan vlan-id
The VLAN view is displayed.
Step 4 Run:
dhcp snooping max-user-number max-user-number
The maximum number of DHCP snooping users allowed on an interface or in a VLAN is set.
By default, a maximum of 512 users can access an interface of the S3700 or a VLAN.
If the maximum number of access users is set on an interface, in a VLAN, or in the system, all
the configurations take effect.
----End

3.6.4 (Optional) Configuring MAC Address Security on an Interface

MAC addresses of DHCP users in the dynamic binding table can be converted to static MAC
addresses, and packets of these users can be forwarded. MAC addresses of static users in the
static binding table cannot be converted to static MAC addresses. Therefore, you need to
configure static MAC addresses for the static users to have the packets forwarded normally.
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
interface interface-type interface-number
The interface view is displayed.
The interface is a user-side interface.
Step 3 Run:
dhcp snooping sticky-mac
MAC address security of DHCP snooping is enabled on the interface.
By default, MAC address security of DHCP snooping is disabled on the S3700.
The dhcp snooping sticky-mac command takes effect only after DHCP snooping is enabled
globally.
If the dhcp snooping sticky-mac command is run, the interface neither learns the MAC address
of the received IP packet nor forwards or sends the received IP packet. The DHCP messages
received by the interface are sent to the CPU of the main control board, and then a dynamic
binding table is generated. After the dynamic binding table is generated, static MAC addresses
are sent to the corresponding interface. That is, dynamic MAC addresses are converted to static
MAC addresses. The static MAC address entry includes information about the MAC address
and VLAN ID of the user. Subsequently, only the packets whose source MAC address matches
the static MAC address can pass through the interface; otherwise, the packets are discarded.
Issue 01 (2011-07-15)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
3 DHCP Snooping Configuration
108

Advertisement

Table of Contents
loading

Table of Contents