Verifying That Mac Move Limiting Is Working Correctly - Juniper JUNOS OS 10.4 - FOR EX REV 1 Manual

For ex series ethernet switches
Table of Contents

Advertisement

Meaning
Related
Documentation

Verifying That MAC Move Limiting Is Working Correctly

Purpose
Action
Meaning
Copyright © 2010, Juniper Networks, Inc.
The MAC limit value for
ge-0/0/2
MAC address was learned and thus added to the MAC cache. An asterisk (*) rather than
an address appears in the
Configuring MAC Limiting (CLI Procedure) on page 3139
Configuring MAC Limiting (J-Web Procedure) on page 3141
Configuring Autorecovery From the Disabled State on Secure or Storm Control Interfaces
(CLI Procedure) on page 3018
Example: Configuring Allowed MAC Addresses to Protect the Switch from DHCP
Snooping Database Alteration Attacks on page 3094
Example: Configuring MAC Limiting, Including Dynamic and Allowed MAC Addresses,
to Protect the Switch from Ethernet Switching Table Overflow Attacks on page 3080
Example: Configuring MAC Limiting to Protect the Switch from DHCP Starvation Attacks
on page 3087
Monitoring Port Security on page 3157
Verify that MAC move limiting is working on the switch.
Display the MAC addresses in the Ethernet switching table when MAC move limiting has
been configured for a VLAN. The following sample shows the results after two of the
hosts on
sent packets after the MAC addresses for those hosts had moved to
ge-0/0/2
other interfaces more than five times in 1 second. The VLAN,
a MAC move limit of
with the action
5
user@switch> show ethernet-switching table
Ethernet-switching table:
VLAN
MAC address
employee-vlan
00:05:85:3A:82:77
employee-vlan
00:05:85:3A:82:79
employee-vlan
00:05:85:3A:82:80
employee-vlan
00:05:85:3A:82:81
employee-vlan
*
employee-vlan
*
The last two lines of the sample output show that MAC addresses for two hosts on
were not learned, because the hosts had been moved back and forth from the
ge-0/0/2
original interfaces more than five times in 1 second.
NOTE: For descriptions of the results of the various action settings—
,
, and
log
none
shutdown
Correctly" on page 3161.
had been set to
, and the output shows that only one
1
column in the first line of the sample output.
MAC address
:
drop
7 entries, 4 learned
Type
Learn
Learn
Learn
Learn
Flood
Flood
—see "Verifying That MAC Limiting Is Working
Chapter 102: Verifying Port Security
employee-vlan
, was set to
Age
Interfaces
0
ge-0/0/1.0
0
ge-0/0/1.0
0
ge-0/0/2.0
0
ge-0/0/2.0
-
ge-0/0/2.0
-
ge-0/0/2.0
drop
3165
,

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junos os 10.4

Table of Contents