JUNOSe 11.0.x IP, IPv6, and IGP Configuration Guide
MAC Address Validation
MAC address validation is a verification process performed on each incoming packet
to prevent spoofing on IP Ethernet-based interfaces, including bridged Ethernet
interfaces. When an incoming packet arrives on a layer 2 interface, the validation
table is used to compare the packet's source IP address with its MAC address. If the
MAC address and IP address match, the packet is forwarded; if it does not match,
the packet is dropped.
NOTE: MAC address validation for bridged Ethernet interfaces is supported only on
OC12 ATM line modules on ERX routers and on OC3/OC12 ATM IOAs on the E120
and E320 routers.
MAC address validation on the E Series router can be accomplished in two ways:
The arp validate command adds the IP-MAC address pair to the validation table
maintained on the physical interface.
If the validation is added statically via the CLI, the IP address–MAC address pairs are
stored in NVS. The entries are used for MAC validation only if MAC validation is
enabled on the interface via the ip mac-validate command.
CAUTION: When you configure an interface using the arp validate command, you
cannot overwrite the ARP values that were added by DHCP.
You can enable or disable MAC address validation on a per interface basis by issuing
the ip mac-validate command. See JUNOSe Physical Layer Configuration Guide or
JUNOSe Link Layer Configuration Guide for information.
A dynamic IP subscriber interface inherits the MAC address validation state (enabled
or disabled) configured for its parent static primary IP interface. See Configuring
Subscriber Interfaces in the JUNOSe Broadband Access Configuration Guide for
information.
arp validate
22
Address Resolution Protocol
You can statically configure it on a physical interface via the arp validate
command
You can enable DHCP to perform the function independently and dynamically.
See JUNOSe Link Layer Configuration Guide .
Use to add IP address–MAC address validation pairs. When validation is enabled,
all packets with the source IP address received on this IP interface are validated
against the IP-MAC entries.
To add a validation pair, specify one of the following:
ipAddress and macAddress of the interface
Need help?
Do you have a question about the IGP - CONFIGURATION GUIDE V11.1.X and is the answer not in the manual?
Questions and answers