Planet WGSW-52040 Configuration Manual page 380

48-port 10/100/1000base-t + 4-port 100/1000x sfp managed switch
Hide thumbs Also See for WGSW-52040:
Table of Contents

Advertisement

of ARP, ND on each INTERFACE VLAN. The number of static or dynamic MAC address on a
port should not exceed the configuration. The number of user on each VLAN should not
exceed the configuration, either.
Limiting the number of MAC and ARP list entry can avoid DOS attack to a certain extent. When
malicious users frequently do MAC or ARP cheating, it will be easy for them to fill the MAC and
ARP list entries of the switch, causing successful DOS attacks.
To summer up, it is very meaningful to develop the number limitation function of MAC and IP in
port, VLAN. Switch can control the number of MAC address of ports and the number ARP, ND
list entry of ports and VLAN through configuration commands.
Limiting the number of dynamic MACand IP of ports:
1. Limiting the number of dynamic MAC. If the number of dynamically learnt MAC address by
the switch is already larger than or equal with the max number of dynamic MAC address, then
shutdown the MAC study function on this port, otherwise, the port can continue its study.
2. Limiting the number of dynamic IP. If the number of dynamically learnt ARP and ND by the
switch is already larger than or equal with the max number of dynamic ARP and ND, then
shutdown the ARP and ND study function of this port, otherwise, the port can continue its
study.
Limiting the number of MAC, ARP and ND of interfaces:
1. Limiting the number of dynamic MAC. If the number of dynamically learnt MAC address by
the VLAN of the switch is already larger than or equal with the max number of dynamic MAC
address, then shutdown the MAC study function of all the ports in this VLAN, otherwise, all the
ports in this VLAN can continue their study (except special ports).
2. Limiting the number of dynamic IP. If the number of dynamically learnt ARP and ND by the
switch is already larger than or equal with the max number of dynamic ARP and ND, then the
VLAN will not study any new ARP or ND, otherwise, the study can be continued.
43.2 The Number Limitation Function of MAC and IP in
Port, VLAN Configuration Task Sequence
1. Enable the number limitation function of MAC and IP on ports
2. Enable the number limitation function of MAC and IP in VLAN
3. Configure the timeout value of querying dynamic MAC
43-159

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents