Mac-Limit - Juniper JUNOS OS 10.4 - FOR EX REV 1 Manual

For ex series ethernet switches
Table of Contents

Advertisement

Complete Software Guide for Junos

mac-limit

Syntax
Hierarchy Level
Release Information
Description
Default
Options
Required Privilege
Level
Related
Documentation
3188
®
OS for EX Series Ethernet Switches, Release 10.4
mac-limit limit action action;
[edit ethernet-switching-options secure-access-port interface (all | interface-name)]
Statement introduced in Junos OS Release 9.0 for EX Series switches.
The default value for the
action
switches.
The
option was modified in Junos OS Release 9.6 for EX Series switches.
shutdown
Specify the number of MAC addresses to dynamically add to the MAC address cache for
this access interface (port) and the action to be taken by the switch if the MAC address
learning limit is exceeded on the interface (port). The MAC address learning limit varies
depending on the switch model. Use the ? help with this command to determine the
learning limit for a switch.
The default action is
drop
.
—Maximum number of MAC addresses (varies depending on switch model).
limit
—(Optional) Action to take when the MAC address limit is exceeded:
action action
—Drop the packet and generate an alarm, an SNMP trap, or a system log entry.
drop
This is the default.
—Do not drop the packet but generate an alarm, an SNMP trap, or a system log
log
entry.
none
—No action.
—Disable the interface and generate an alarm. If you have configured the
shutdown
switch with the
port-error-disable
automatically upon expiration of the specified disable timeout. If you have not
configured the switch for autorecovery from port error disabled conditions, you can
bring up the disabled interfaces by running the
command.
system—To view this statement in the configuration.
system–control—To add this statement to the configuration.
allowed-mac on page 3175
Example: Configuring Port Security, with DHCP Snooping, DAI, MAC Limiting, and MAC
Move Limiting, on an EX Series Switch on page 3073
Example: Configuring MAC Limiting, Including Dynamic and Allowed MAC Addresses,
to Protect the Switch from Ethernet Switching Table Overflow Attacks on page 3080
Example: Configuring MAC Limiting to Protect the Switch from DHCP Starvation Attacks
on page 3087
option was changed in Junos OS Release 9.5 for EX Series
statement, the disabled interface recovers
clear ethernet-switching port-error
Copyright © 2010, Juniper Networks, Inc.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junos os 10.4

Table of Contents