Example: Configuring Dhcp Snooping, Dai , And Mac Limiting On An Ex Series Switch With Access To A Dhcp Server Through A Second Switch - Juniper JUNOS OS 10.3 - SOFTWARE Manual

For ex series ethernet switches
Hide thumbs Also See for JUNOS OS 10.3 - SOFTWARE:
Table of Contents

Advertisement

Purpose
Action
Meaning
Related
Documentation
Example: Configuring DHCP Snooping, DAI , and MAC Limiting on an EX Series Switch
with Access to a DHCP Server Through a Second Switch
Copyright © 2010, Juniper Networks, Inc.
Verifying That Allowed MAC Addresses Are Working Correctly on the Switch
Verify that allowed MAC addresses are working on the switch.
Display the MAC cache information:
user@switch> show ethernet-switching table
Ethernet-switching table:
VLAN
MAC address
employee-vlan
00:05:85:3A:82:80
employee-vlan
00:05:85:3A:82:81
employee-vlan
00:05:85:3A:82:83
employee-vlan
00:05:85:3A:82:85
employee-vlan
00:05:85:3A:82:88
employee-vlan
*
The output shows that the five MAC addresses configured as allowed MAC addresses
have been learned and are displayed in the MAC cache. The last MAC address in the list,
one that had not been configured as allowed, has not been added to the list of learned
addresses.
Example: Configuring Port Security, with DHCP Snooping, DAI, MAC Limiting, and MAC
Move Limiting, on an EX Series Switch on page 2849
Configuring MAC Limiting (CLI Procedure) on page 2915
Configuring MAC Limiting (J-Web Procedure) on page 2917
You can configure DHCP snooping, dynamic ARP inspection (DAI), and MAC limiting on
the access interfaces of EX Series switches to protect the switch and the Ethernet LAN
against address spoofing and Layer 2 denial-of-service (DoS) attacks. To obtain those
basic settings, you can use the switch's default configuration for port security, configure
the MAC limit, and enable DHCP snooping and DAI on a VLAN. You can configure those
features when the DHCP server is connected to a different switch from the one to which
the DHCP clients (network devices) are connected.
This example describes how to configure port security features on an EX Series switch
whose hosts obtain IP addresses and lease times from a DHCP server connected to a
second switch:
Requirements on page 2874
Overview and Topology on page 2874
Configuring a VLAN, Interfaces, and Port Security Features on Switch 1 on page 2876
Configuring a VLAN and Interfaces on Switch 2 on page 2878
Verification on page 2879
Chapter 94: Examples: Port Security Configuration
6 entries, 5 learned
Type
Learn
Learn
Learn
Learn
Learn
Flood
Age
Interfaces
0
ge-0/0/2.0
0
ge-0/0/2.0
0
ge-0/0/2.0
0
ge-0/0/2.0
0
ge-0/0/2.0
-
ge-0/0/2.0
2873

Advertisement

Table of Contents
loading

Table of Contents