Mac Move Limiting - Dell PowerConnect J-EX4200-24T Software Manual

J series; j-ex series
Table of Contents

Advertisement

Dell PowerConnect J-Series Ethernet Switch Complete Software Guide for Junos OS

MAC Move Limiting

Actions for MAC Limiting and MAC Move Limiting
2558
Allowed MAC—You configure specific "allowed" MAC addresses for the access interface.
Any MAC address that is not in the list of configured addresses is not learned and the
switch logs the message. Allowed MAC binds MAC addresses to a VLAN so that the
address does not get registered outside the VLAN. If an allowed MAC setting conflicts
with a dynamic MAC setting, the allowed MAC setting takes precedence.
NOTE: If you do not want the switch to log messages received for invalid
MAC addresses on an interface that has been configured for specific "allowed"
MAC addresses, you can disable the logging by configuring the
no-allowed-mac-log
MAC move limiting causes the switch to track the number of times a MAC address can
move to a new interface (port). It can help to prevent MAC spoofing, and it can also
detect and prevent loops.
If a MAC address moves more than the configured number of times within one second,
the switch performs the configured action. You can configure MAC move limiting to apply
to all VLANs or to a specific VLAN.
You can choose to have one of the following actions performed when the limit of MAC
addresses or the limit of MAC moves is exceeded:
—Drop the packet and generate an alarm, an SNMP trap, or a system log entry.
drop
This is the default.
—Do not drop the packet but generate an alarm, an SNMP trap, or a system log
log
entry.
none
—Take no action.
—Disable the interface and generate an alarm. If you have configured the
shutdown
switch with the
port-error-disable
automatically upon expiration of the specified disable timeout. If you have not
configured the switch for autorecovery from port error disabled conditions, you can
bring up the disabled interfaces by running the
command.
See descriptions of results of these various action settings in "Verifying That MAC Limiting
Is Working Correctly" on page 2657.
If you have set a MAC limit to apply to all interfaces on the switch, you can override that
setting for a particular interface by specifying action
on an Interface to Override a MAC Limit Applied to All Interfaces (CLI Procedure)" on
page 2642.
statement.
statement, the disabled interface recovers
clear ethernet-switching port-error
none
. See "Setting the none Action

Advertisement

Table of Contents
loading

Table of Contents