Layer 2 Security; Port Security - Cisco ASR 9000 Series Configuration Manuallines

L2vpn and ethernet services configuration guide
Hide thumbs Also See for ASR 9000 Series:
Table of Contents

Advertisement

Layer 2 Security

Known Unicast traffic consists of frames sent to bridge ports that were learned from that port using MAC
learning.
Traffic flooding is performed for broadcast, multicast and unknown unicast destination address.
Table 3: Split Horizon Groups Supported in Cisco IOS-XR
Split Horizon
Group
0
1
2
Important notes on Split Horizon Groups:
• All bridge ports or PWs that are members of a bridge domain must belong to one of the three groups.
• By default, all bridge ports or PWs are members of group 0.
• The VFI configuration submode under a bridge domain configuration indicates that members under this
• A PW that is configured in group 0 is called an Access Pseudowire.
• The split-horizon group command is used to designate bridge ports or PWs as members of group 2.
• The ASR9000 only supports one VFI group.
Layer 2 Security
These topics describe the Layer 2 VPN extensions to support Layer 2 security:

Port Security

Use port security with dynamically learned and static MAC addresses to restrict a port's ingress traffic by
limiting the MAC addresses that are allowed to send traffic into the port. When secure MAC addresses are
assigned to a secure port, the port does not forward ingress traffic that has source addresses outside the group
of defined addresses. If the number of secure MAC addresses is limited to one and assigned a single secure
MAC address, the device attached to that port has the full bandwidth of the port.
These port security features are supported:
• Limits the MAC table size on a bridge or a port.
• Facilitates actions and notifications for a MAC address.
• Enables the MAC aging time and mode for a bridge or a port.
• Filters static MAC addresses on a bridge or a port.
• Marks ports as either secure or nonsecure.
• Enables or disables flooding on a bridge or a port.
L2VPN and Ethernet Services Configuration Guide for Cisco ASR 9000 Series Routers, IOS XR Release 6.3.x
216
Who belongs to this Group?
Default—any member not
covered by groups 1 or 2.
Any PW configured under VFI.
Any AC or PW configured with
split-horizon keyword.
domain are included in group 1.
Implementing Multipoint Layer 2 Services
Multicast within
Unicast within Group
Group
Yes
Yes
No
No
No
No

Advertisement

Table of Contents
loading

Table of Contents