96
C
18: MAC A
HAPTER
Disabling MAC Address
learning for a VLAN
Displaying and
Maintaining a MAC
Address Table
Configuration
Example
T
M
DDRESS
ABLE
ANAGEMENT
You can disable a switch from learning MAC addresses in specific VLANs to improve
stability and security for the users belong to these VLANs and prevent unauthorized
accesses.
Table 72 Disable MAC address learning for a VLAN
Operation
Enter system view
Enter VLAN view
Disable the switch from
learning MAC
addresses in the VLAN
To verify your configuration, you can display information about the MAC address
table by executing the display command in any view.
Table 73 Display and maintain the MAC address table
Operation
Display information about the MAC address
table
Display the aging time of the dynamic MAC
address entries in the MAC address table
Network requirements
Log into the switch through the Console port.
■
Set the aging time of the dynamic MAC address entries to 500 seconds.
■
Add a static MAC address entry for GigabitEthernet1/0/2 port (assuming that the
■
port belongs to VLAN 1), with the MAC address of 00e0-fc35-dc71.
Network diagram
Figure 29 Network diagram for MAC address table configuration
Command
system-view
vlan vlan-id
mac-address max-mac-count 0
Command
display mac-address [ display-option ]
display mac-address aging-time
Console port
Console port
Switch
Switch
Switch
Switch
Description
Required
By default, a switch learns MAC
addresses in any VLAN.
Internet
Internet
Internet
Internet
t
Network port
t
Network port