Configuration Examples - Huawei Quidway S3700 Series Configuration Manual

Hide thumbs Also See for Quidway S3700 Series:
Table of Contents

Advertisement

Quidway S3700 Series Ethernet Switches
Configuration Guide - Security
To manually delete ND dynamic binding entries, run the following command in the user view
or in the system view.
Procedure
l
----End

11.5 Configuration Examples

This section provides a configuration example of ND snooping.
11.5.1 Example for Configuring ND Snooping on a Layer 2 Network
This section describes the procedure for configuring ND snooping, including the configuration
of the trusted interface and the ND dynamic binding table.
Networking Requirements
As shown in
and the ND server. To protect the Switch against the attacks of a bogus ND server, it is required
that ND snooping be configured on the Switch and the network-side interface of the carrier be
configured as the trusted interface. By maintaining the prefix management table and ND dynamic
binding table, the Switch ensures that authorized users access the network and prevents
unauthorized users from attacking network devices and authorized users.
Figure 11-2 Networking diagram for configuring ND snooping on a Layer 2 network
GE0/0/2
Issue 01 (2011-07-15)
NOTE
After the networking environment changes, ND dynamic binding entries do not age immediately. However,
the following information in ND dynamic binding entries may change, causing packet forwarding failure:
l
VLAN ID in packets
l
Interface information
Before changing the networking environment, clear all ND dynamic binding entries manually so that a
device generates a new ND dynamic binding table according to the new networking environment.
Run the reset nd snooping user-bind [ interface interface-type interface-number | ipv6-
address ipv6-address | mac-address mac-address | vlan vlan-id ] command to reset the
ND dynamic binding table.
Figure
11-2, the Switch is deployed in the layer 2 network between the user network
Switch
GE0/0/1
L2
Router
network
(ND Server)
User
network
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
L3
network
11 ND Snooping Configuration
259

Advertisement

Table of Contents
loading

Table of Contents