Limiting Dynamic Mac Addresses - Extreme Networks ExtremeWare XOS Guide Manual

Concepts guide
Hide thumbs Also See for ExtremeWare XOS Guide:
Table of Contents

Advertisement

Security
NOTE
You can either limit dynamic MAC FDB entries, or lock down the current MAC FDB entries, but not both.
You can also prioritize or stop packet flows based on the source MAC address of the ingress VLAN or
the destination MAC address of the egress VLAN.

Limiting Dynamic MAC Addresses

You can set a predefined limit on the number of dynamic MAC addresses that can participate in the
network. After the FDB reaches the MAC limit, all new source MAC addresses are blackholed at both
the ingress and egress points. These dynamic blackhole entries prevent the MAC addresses from
learning and responding to Internet control message protocol (ICMP) and address resolution protocol
(ARP) packets.
To limit the number of dynamic MAC addresses that can participate in the network, use the
option in following command:
learning
configure ports <portlist> vlan <vlan name> [limit-learning <number> | lock-learning |
unlimited-learning | unlock-learning]
This command specifies the number of dynamically-learned MAC entries allowed for these ports in this
VLAN. The range is 0 to 500,000 addresses.
When the learned limit is reached, all new source MAC addresses are blackholed at the ingress and
egress points. This prevent these MAC addresses from learning and responding to Internet control
message protocol (ICMP) and address resolution protocol (ARP) packets.
Dynamically learned entries still get aged and can be cleared. If entries are cleared or aged out after the
learning limit has been reached, new entries will then be able to be learned until the limit is reached
again.
Permanent static and permanent dynamic entries can still be added and deleted using the
and
fdbentry
show fdb
For ports that have a learning limit in place, the following traffic will still flow to the port:
Packets destined for permanent MAC addresses and other non-blackholed MAC addresses
Broadcast traffic
EDP traffic
Traffic from the permanent MAC and any other non-blackholed MAC addresses will still flow from the
virtual port.
To remove the learning limit, use the
configure ports <portlist> vlan <vlan name> [limit-learning <number> | lock-learning |
unlimited-learning | unlock-learning]
To verify the configuration, use the following commands:
show vlan <vlan name> security
ExtremeWare XOS 11.1 Concepts Guide
commands. These override any dynamically learned entries.
unlimited-learning
option from the following command:
limit-
create
226

Advertisement

Table of Contents
loading

This manual is also suitable for:

Extremeware xos 11.1

Table of Contents