Alcatel-Lucent 7330 Product Information Manual page 108

Intelligent services access manager
Hide thumbs Also See for 7330:
Table of Contents

Advertisement

1 — ONT and MDU overview
If re-authentication is enabled on a port, the Session Timeout value returned by
RADIUS service is used as the re-authentication period. If the RADIUS server does
not return a Session Timeout value, the re-authentication timer for the port that is
configured by the management system is used.
If there is no response from an RADIUS server for re-authentication due to an NT
card switchover, the P-OLT treats the re-authentication as a successful one for 30
min.
If re-authentication is disabled for a port, the Session Timeout value returned by
RADIUS server is used to terminate the sessions. Re-authentication initiated by the
management system is not required.
During re-authentication, traffic to and from the user is not interrupted. The port
forwards bidirectional traffic until re-authentication is completed. If
re-authentication fails, the port is changed to unauthorized state.
An EAP Request Identity message is sent to the port when the re-authentication timer
expires.
1.10
Anti-spoofing mechanism
The system supports two features to protect against spoofing:
gratuitous ARP discard
source address anti-spoofing
Gratuitous ARP discard
A gratuitous ARP request is an ARP packet where the sender IP address and the
target IP address are the same. Attackers can use gratuitous ARP requests to corrupt
the ARP cache of a router by sending out a gratuitous ARP request that claims to be
the default router.
The system supports a discard mechanism that filters incoming traffic for gratuitous
ARP requests. When gratuitous ARP discard is enabled, incoming gratuitous ARP
requests are discarded.
Gratuitous ARP discard is implemented on a per ONT UNI port basis using TL1. See
the appropriate P-OLT TL1 documentation.
Source address anti-spoofing
Source address spoofing is an attempt to gain entry to a system by posing as a trusted
source. Although the packet cannot be routed back to the initial source, source
address spoofing can lead to unnecessary network congestion and to possible denial
of service.
1-24
Note —
Gratuitous ARP discard only applies for residential bridge
VLANs; in VLAN cross-connect mode, gratuitous ARP requests are
always forwarded.
March 2011
ONT Product Information Guide Edition 01
Alcatel-Lucent 7330/7302 ISAM FTTN R04.02.42a
3FE 54199 AAAA TCZZA

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

7302

Table of Contents