Verifying That Mac Limiting Is Working Correctly - Juniper JUNOS OS 10.4 - FOR EX REV 1 Manual

For ex series ethernet switches
Table of Contents

Advertisement

Verifying That MAC Limiting Is Working Correctly

Verifying That MAC Limiting for Dynamic MAC Addresses Is Working Correctly
Purpose
Action
Meaning
Copyright © 2010, Juniper Networks, Inc.
Monitoring Port Security on page 3157
MAC limiting protects against flooding of the Ethernet switching table. MAC limiting sets
a limit on the number of MAC addresses that can be learned on a single Layer 2 access
interface (port).
Junos OS provides two MAC limiting methods:
Maximum number of dynamic MAC addresses allowed per interface—When the limit
is exceeded, incoming packets with new MAC addresses are dropped.
Specific "allowed" MAC addresses for the access interface—Any MAC address that is
not in the list of configured addresses is not learned.
To verify MAC limiting configurations:
Verifying That MAC Limiting for Dynamic MAC Addresses Is Working
1.
Correctly on page 3161
Verifying That Allowed MAC Addresses Are Working Correctly on page 3162
2.
Verifying Results of Various Action Settings When the MAC Limit Is
3.
Exceeded on page 3162
Customizing the Ethernet Switching Table Display to View Information for a Specific
4.
Interface on page 3164
Verify that MAC limiting for dynamic MAC addresses is working on the switch.
Display the MAC addresses that have been learned. The following sample output shows
the results when two packets were sent from hosts on
were sent from hosts on
ge-0/0/2
action
:
drop
user@switch> show ethernet-switching table
Ethernet-switching table:
VLAN
MAC address
employee-vlan
*
employee-vlan
00:05:85:3A:82:77
employee-vlan
00:05:85:3A:82:79
employee-vlan
00:05:85:3A:82:80
employee-vlan
00:05:85:3A:82:81
employee-vlan
00:05:85:3A:82:83
employee-vlan
00:05:85:3A:82:85
The sample output shows that with a MAC limit of
fifth MAC address on
ge-0/0/2
address was not learned, and thus an asterisk (*) rather than an address appears in the
column in the first line of the sample output.
MAC address
ge-0/0/1
, with both interfaces set to a MAC limit of
7 entries, 6 learned
Type
Flood
Learn
Learn
Learn
Learn
Learn
Learn
4
for each interface, the packet for a
was dropped because it exceeded the MAC limit. The
Chapter 102: Verifying Port Security
and five packets requests
4
with the
Age
Interfaces
-
ge-0/0/2.0
0
ge-0/0/1.0
0
ge-0/0/1.0
0
ge-0/0/2.0
0
ge-0/0/2.0
0
ge-0/0/2.0
0
ge-0/0/2.0
3161

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junos os 10.4

Table of Contents