Mac Limit: Vlan Security - ZyXEL Communications VES1724-56 User Manual

24-port temperature-hardened vdsl2 box dslam
Hide thumbs Also See for VES1724-56:
Table of Contents

Advertisement

Chapter 19 MAC Limit
The following table describes the labels in this screen.
Table 79 MAC Limit
LABEL
Active
Port
Active SLF drop
MAC Spoofing
Address
Learning
Limited Number
of Learnt MAC
Address

19.2.1 MAC Limit: VLAN Security

Click the VLAN Security link in the Advanced Application > MAC Limit screen to display VLAN
security settings as the following screen. Use this screen to limit how many MAC addresses the
Switch can dynamically learn on individual VLANs.
Figure 118 MAC Limit: VLAN Security
The following table describes the labels in this screen.
Table 80 MAC Limit: VLAN Security
LABEL
Active
192
DESCRIPTION
Select this check box to enable the MAC limit feature on the Switch. Clear the check box to
disable the feature. You must enable this for the Switch to apply the MAC limit settings for
individual ports.
This field displays the number of the port. Use the * entry to configure settings for all of the
subscriber ports.
SLF stands for Source MAC address Look up Fail (SLF), which means the source MAC does
not exist on the Switch. Select this check box to enable the MAC limit feature on this port.
The Switch only forwards packets whose source MAC addresses can be found in the MAC
address table and drops the other packets.
Clear this check box to have the Switch also forward the packets whose source MAC
addresses do not exist in the MAC address table.
Select this check box to have the Switch detect whether a MAC address is connected to more
than one port. When the Switch detects a spoofed MAC address on a subscriber port, it drops
all the packets from the MAC address.
MAC address learning reduces outgoing broadcast traffic. Select this to have the Switch
dynamically learn MAC addresses on the port.
Specify how many MAC addresses the Switch can dynamically learn on this port. For
example, if you set this field to "5" on port 2, then only the devices with the first five learned
MAC addresses can access port 2 at any one time. A sixth device would have to wait until
one of the five learned MAC addresses aged out. MAC address aging time can be set in the
Basic Setting > Switch Setup screen.
The valid range is from 0 to 16K (16384). "0" means this feature is disabled, so the switch
will learn MAC addresses up to the global limit of 16K.
DESCRIPTION
Select this to limit the number of MAC addresses the Switch can dynamically learn on
individual VLANs.
VES1724-56 User's Guide

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents