Chapter14AccessSecurityConguration
4.(Optional)QuerythecongurationofMACaddressanti-spoong.
ZXAN(config)#showsecuritymac-anti-spoofingconfiguration
mac-move-report:enable
mac-move-reportinterval:30[minutes]
mac-anti-spoofing:enable
uplink-protect:disable
5.(Optional)QuerytheMACmovelog.
ZXAN#showsecuritymac-move-log
Flag*--macMoveisforbiddenbysystem.
thetotalmac-move-lognum:2
-------------------------------------------------------------------------
mac-addressvlancfgMacProtectmoveToPortmoveToIfIdmoveCount
indextrapFlagdetectorqueryPortmoveFromPortmoveFromIfIdtrapCount
-------------------------------------------------------------------------
0002.0304.0506100UNNEEDinner-port_1/12/1unknown(0)1
1SENDEDMPUNNEEDinner-port_1/5/1unknown(0)1
-------------------------------------------------------------------------
0002.0304.0507100UNNEEDinner-port_1/12/2unknown(0)1
2*SENDEDMPUNNEEDinner-port_1/5/1unknown(0)1
–EndofSteps–
14.2.2ConfiguringtheServiceGatewayMACAnti-Spoofing
ServicegatewayMACaddressanti-spoongpreventsmaliciousMACaddressspoong
betweenuserportsandpermitsMACaddresslearningbetweenuplinkports.
Context
TheZXA10C300supportsthefollowingfeaturesbyservicegatewayMACanti-spoong:
lAMACaddresslearntbyauserportcanbelearntbyanuplinkportaswell.
lThesameMACaddresscannotbelearntbytwouserports.
lThesameMACaddresscanbelearntbymultipleuplinkports.
Steps
1.EnableglobalMACaddressanti-spoongfunction.
ZXAN(config)#securitymac-anti-spoofingenable
2.EnableMACaddressanti-spoongfunctionwithuplinkprotection.
ZXAN(config)#securitymac-anti-spoofinguplink-protectenable
3.(Optional)QuerythecongurationofMACaddressanti-spoong.
ZXAN(config)#showsecuritymac-anti-spoofingconfiguration
14-9
SJ-20130520164529-007|2013-06-30(R1.0)ZTEProprietaryandCondential