4. (Optional) Run the security anti-macspoofing exclude command to configure
the types of packets for which MAC address anti-spoofing does not take effect,
such as Internet Group Management Protocol (IGMP) packets.
– Enable IP address anti-spoofing on ONUs.
IP address anti-spoofing can be enabled or disabled at three levels: global, VLAN,
and service port levels. This function takes effect only after it is enabled at the three
levels. Among the three levels, IP address anti-spoofing is disabled only at the global
level by default.
1. In global config mode, run the security anti-ipspoofing enable command to
enable IP address anti-spoofing at the global level.
2. In VLAN service profile mode, run the security anti-ipspoofing enable
command to enable IP address anti-spoofing at the VLAN level.
3. Run the security anti-ipspoofing service-port serviceport-id enable command
to enable IP address anti-spoofing at the service port level.
----End
13.3.5.9 Configuring Network Protectio
The base station access service has high requirements on reliability. Therefore, network
protection solutions must be configured in the upstream and downstream directions.
Context
The protection solutions supported in this scenario are Type B protection and Type C single-
homing protection.
Procedure
l Configure the Type B protection.
Figure 13-18 shows the Type B protection networking diagram.
Figure 13-18 Type B protection
OLT
ONU
Splitter
Backbone Fibers
Protection
Active
Standby
Configure redundancy backup for ports 0/3/1 and 0/3/2 on the same GPON board on OLT.
When port 0/3/1 fails, the system can automatically switch to port 0/3/2.
SmartAX MA5600T/MA5603T/MA5608T Multi-service
Access Module
Commissioning and Configuration Guide
13 FTTO Configuration (Large-sized Enterprise Access)
Issue 01 (2014-04-30) Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
1341