Juniper JUNOS OS 10.3 - SOFTWARE Manual page 2968

For ex series ethernet switches
Hide thumbs Also See for JUNOS OS 10.3 - SOFTWARE:
Table of Contents

Advertisement

Complete Software Guide for Junos
Table 370: Components of the Port Security Topology (continued)
Properties
Interfaces in
employee-vlan
Interface for DHCP server
Configuration
CLI Quick
Configuration
Step-by-Step
Procedure
Results
Verification
2872
®
OS for EX Series Ethernet Switches, Release 10.3
Settings
ge-0/0/1
ge-0/0/8
In this example, the switch has already been configured as follows:
Secure port access is activated on the switch.
DHCP snooping is enabled on the VLAN
All access ports are untrusted, which is the default setting.
To configure allowed MAC addresses to protect the switch against DHCP snooping
database alteration attacks:
To quickly configure some allowed MAC addresses on an interface, copy the following
commands and paste them into the switch terminal window:
[edit ethernet-switching-options secure-access-port]
set interface ge-0/0/2 allowed-mac 00:05:85:3A:82:80
set interface ge-0/0/2 allowed-mac 00:05:85:3A:82:81
set interface ge-0/0/2 allowed-mac 00:05:85:3A:82:83
set interface ge-0/0/2 allowed-mac 00:05:85:3A:82:85
set interface ge-0/0/2 allowed-mac 00:05:85:3A:82:88
To configure some allowed MAC addresses on an interface:
Configure the five allowed MAC addresses on an interface:
[edit ethernet-switching-options secure-access-port]
user@switch# set interface ge-0/0/2 allowed-mac 00:05:85:3A:82:80
user@switch# set interface ge-0/0/2 allowed-mac 00:05:85:3A:82:81
user@switch# set interface ge-0/0/2 allowed-mac 00:05:85:3A:82:83
user@switch# set interface ge-0/0/2 allowed-mac 00:05:85:3A:82:85
user@switch# set interface ge-0/0/2 allowed-mac 00:05:85:3A:82:88
Check the results of the configuration:
[edit ethernet-switching-options secure-access-port]
user@switch# show
interface ge-0/0/2.0 {
allowed-mac [ 00:05:85:3a:82:80 00:05:85:3a:82:81 00:05:85:3a:82:83 00:05:85
:3a:82:85 00:05:85:3a:82:88 ];
}
To confirm that the configuration is working properly:
Verifying That Allowed MAC Addresses Are Working Correctly on the Switch on page 2873
,
,
,
ge-0/0/2
ge-0/0/3
ge-0/0/8
.
employee-vlan
Copyright © 2010, Juniper Networks, Inc.

Advertisement

Table of Contents
loading

Table of Contents