Mff Overview - Huawei Quidway S3700 Series Configuration Manual

Hide thumbs Also See for Quidway S3700 Series:
Table of Contents

Advertisement

Quidway S3700 Series Ethernet Switches
Configuration Guide - Security

8.1 MFF Overview

This section describes the principle of the MFF function.
Background
In traditional Ethernet solutions, VLANs are usually configured on switches to implement Layer
2 isolation and Layer 3 interconnection between clients. When many users need to be isolated
on Layer 2, a large number of VLANs are required. In addition, to enable the clients to
communicate on Layer 3, each VLAN must be assigned an IP network segment and each
VLANIF interface needs an IP address. This wastes IP addresses. In addition, the network is
easy to attack and the malicious attacks from users on the network cannot be prevented.
The MFF function provides a solution to this problem and implements Layer 2 isolation and
Layer 3 interconnection between the clients in a broadcast domain. The MFF intercepts the ARP
requests from users and replies with ARP responses containing the MAC address of the gateway
through the ARP proxy. In this manner, the MFF forces users to send all traffic, including the
traffic on the same subnet, to the gateway so that the gateway can monitor data traffic. This
prevents malicious attacks and improves network security.
MFF Interface Role
Two types of interfaces are involved in the MFF function: network interface and user interface.
l
l
Issue 01 (2011-07-15)
User interface
A user interface refers to an interface connected to a network terminal.
The user interface processes different packets as follows:
– Sends ARP and DHCP packets to the CPU.
– Allows ARP, DHCP, IGMP, EAPOL packets to pass through.
– Allows the unicast packets whose destination MAC address is the MAC address of the
gateway to pass through and discards other packets if the interface has learned the MAC
address of the gateway; discards all packets if the interface does not learn the MAC
address of the gateway.
– Rejects multicast packets and broadcast packets.
Network interface
A network interface is an interface connected to another network device, for example, an
access switch, an aggregate switch, or a gateway.
MFF processes packets on a network interface as follows:
– Allows multicast and DHCP packets to pass through.
– Sends ARP packets to the CPU.
– Forwards packets directly without processing.
NOTE
l
The interfaces receiving packets sent from the gateway must be configured as network-side interfaces.
l
The interface role is irrelevant to the position of the interface on a network.
l
On a VLAN where MFF is enabled, an interface must be a network interface or a user interface.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
8 MFF Configuration
202

Advertisement

Table of Contents
loading

Table of Contents