Juniper JUNOS OS 10.3 - SOFTWARE Manual page 3013

For ex series ethernet switches
Hide thumbs Also See for JUNOS OS 10.3 - SOFTWARE:
Table of Contents

Advertisement

Configuring MAC Limiting (J-Web Procedure)
Copyright © 2010, Juniper Networks, Inc.
MAC limiting protects against flooding of the Ethernet switching table on an EX Series
switch. MAC limiting sets a limit on the number of MAC addresses that can be learned
on a single Layer 2 access interface (port).
Junos OS provides two MAC limiting methods:
Maximum number of dynamic MAC addresses allowed per interface—If the limit is
exceeded, incoming packets with new MAC addresses are dropped.
Specific "allowed" MAC addresses for the access interface—Any MAC address that is
not in the list of configured addresses is not learned.
You configure MAC limiting for each interface, not for each VLAN. You can specify the
maximum number of dynamic MAC addresses that can be learned on a single Layer 2
access interface or on all Layer 2 access interfaces. The default action that the switch
will take if that maximum number is exceeded is
alarm, an SNMP trap, or a system log entry.
To enable MAC limiting on one or more interfaces using the J-Web interface:
Select
Configure>Security>Port Security
1.
Select one or more interfaces from the
2.
Click the
button. If a message appears asking whether you want to enable port
Edit
3.
security, click
Yes
.
To set a dynamic MAC limit:
4.
Type a limit value in the
1.
Select an action from the
2.
action when the MAC limit is exceeded. If you do not select an action, the switch
applies the default action,
Log—Generate a system log entry, an SNMP trap, or an alarm.
Drop—Drop the packets and generate a system log entry, an SNMP trap, or an
alarm. (Default)
Shutdown—Shut down the VLAN and generate an alarm. You can mitigate the
effect of this option by configuring the switch for autorecovery from the disabled
state and specifying a
From the Disabled State on Secure or Storm Control Interfaces (CLI Procedure)"
on page 2796. If you have not configured autorecovery from the disabled state, you
can bring up the interfaces by running the
command.
None— No action to be taken.
To add allowed MAC addresses:
5.
—drop the packet and generate an
drop
.
Interface List
.
box.
MAC Limit
MAC Limit Action
box (optional). The switch takes this
.
drop
value. See "Configuring Autorecovery
disable timeout
clear ethernet-switching port-error
Chapter 95: Configuring Port Security
2917

Advertisement

Table of Contents
loading

Table of Contents