Verifying That Mac Move Limiting Is Working Correctly - Juniper JUNOS OS 10.3 - SOFTWARE Manual

For ex series ethernet switches
Hide thumbs Also See for JUNOS OS 10.3 - SOFTWARE:
Table of Contents

Advertisement

Meaning
Related
Documentation

Verifying That MAC Move Limiting Is Working Correctly

Purpose
Action
Meaning
Copyright © 2010, Juniper Networks, Inc.
v1
00:00:06:00:00:00 Learn
The MAC limit value for
ge-0/0/2
MAC address was learned and thus added to the MAC cache. An asterisk (*) rather than
an address appears in the
Configuring MAC Limiting (CLI Procedure) on page 2915
Configuring MAC Limiting (J-Web Procedure) on page 2917
Configuring Autorecovery From the Disabled State on Secure or Storm Control Interfaces
(CLI Procedure) on page 2796
Example: Configuring Allowed MAC Addresses to Protect the Switch from DHCP
Snooping Database Alteration Attacks on page 2870
Example: Configuring MAC Limiting, Including Dynamic and Allowed MAC Addresses,
to Protect the Switch from Ethernet Switching Table Overflow Attacks on page 2856
Example: Configuring MAC Limiting to Protect the Switch from DHCP Starvation Attacks
on page 2863
Monitoring Port Security on page 2933
Verify that MAC move limiting is working on the switch.
Display the MAC addresses in the Ethernet switching table when MAC move limiting has
been configured for a VLAN. The following sample shows the results after two of the
hosts on
sent packets after the MAC addresses for those hosts had moved to
ge-0/0/2
other interfaces more than five times in 1 second. The VLAN,
a MAC move limit of
with the action
5
user@switch> show ethernet-switching table
Ethernet-switching table:
VLAN
MAC address
employee-vlan
00:05:85:3A:82:77
employee-vlan
00:05:85:3A:82:79
employee-vlan
00:05:85:3A:82:80
employee-vlan
00:05:85:3A:82:81
employee-vlan
*
employee-vlan
*
The last two lines of the sample output show that MAC addresses for two hosts on
were not learned, because the hosts had been moved back and forth from the
ge-0/0/2
original interfaces more than five times in 1 second.
had been set to
, and the output shows that only one
1
column in the first line of the sample output.
MAC address
:
drop
7 entries, 4 learned
Type
Learn
Learn
Learn
Learn
Flood
Flood
Chapter 96: Verifying Port Security
0 ge-2/0/0.0
employee-vlan
, was set to
Age
Interfaces
0
ge-0/0/1.0
0
ge-0/0/1.0
0
ge-0/0/2.0
0
ge-0/0/2.0
-
ge-0/0/2.0
-
ge-0/0/2.0
2941

Advertisement

Table of Contents
loading

Table of Contents