Juniper JUNOS OS 10.4 - FOR EX REV 1 Manual page 3187

For ex series ethernet switches
Table of Contents

Advertisement

Verification
Purpose
Action
Meaning
Related
Documentation
Example: Configuring a DHCP Server Interface as Untrusted to Protect the Switch from
Rogue DHCP Server Attacks
Copyright © 2010, Juniper Networks, Inc.
allowed-mac [ 00:05:85:3a:82:80 00:05:85:3a:82:81 00:05:85:3a:82:83 00:05:85
:3a:82:85 ];
}
To confirm that the configuration is working properly:
Verifying That MAC Limiting Is Working Correctly on the Switch on page 3083
Verifying That MAC Limiting Is Working Correctly on the Switch
Verify that MAC limiting is working on the switch.
Display the MAC cache information after DHCP requests have been sent from hosts on
, with the interface set to a MAC limit of
ge-0/0/1
allowed MAC addresses have been configured on interface
user@switch> show ethernet-switching table
Ethernet-switching table:
VLAN
MAC address
employee-vlan
00:05:85:3A:82:71
employee-vlan
00:05:85:3A:82:74
employee-vlan
00:05:85:3A:82:77
employee-vlan
00:05:85:3A:82:79
employee-vlan
*
employee-vlan
00:05:85:3A:82:80
employee-vlan
00:05:85:3A:82:81
employee-vlan
00:05:85:3A:82:83
employee-vlan
00:05:85:3A:82:85
employee-vlan
*
The sample output shows that with a MAC limit of
for a fifth MAC address on
that only the specified allowed MAC addresses have been learned on the
interface.
Example: Configuring Port Security, with DHCP Snooping, DAI, MAC Limiting, and MAC
Move Limiting, on an EX Series Switch on page 3073
Configuring MAC Limiting (CLI Procedure) on page 3139
Configuring MAC Limiting (J-Web Procedure) on page 3141
In a rogue DHCP server attack, an attacker has introduced a rogue server into the network,
allowing it to give IP address leases to the network's DHCP clients and to assign itself as
the gateway device.
Chapter 100: Examples: Port Security Configuration
with the action
4
5 entries, 4 learned
Type
Learn
Learn
Learn
Learn
Flood
Learn
Learn
Learn
Learn
Flood
4
was dropped because it exceeded the MAC limit and
ge-0/0/1
, and after four
drop
ge/0/0/2
:
Age
Interfaces
0
ge-0/0/1.0
0
ge-0/0/1.0
0
ge-0/0/1.0
0
ge-0/0/1.0
0
ge-0/0/1.0
0
ge-0/0/2.0
0
ge-0/0/2.0
0
ge-0/0/2.0
0
ge-0/0/2.0
-
ge-0/0/2.0
for the interface, the DHCP request
ge-0/0/2
3083

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junos os 10.4

Table of Contents