HP 6125G HP 6125G & 6125G/XG Blade Switches Security Configuration Gui - Page 271

Automatic mode, Working mechanism, Protocols and standards, Configuring MFF

Page 271 highlights

The MFF device also forges ARP requests to get the gateway's MAC address based on ARP snooping entries. After learning the gateway's MAC address and then receiving an ARP packet with a different source MAC address from the default gateway, the MFF device will replace the old MAC address with the new one. Automatic mode The automatic mode applies to the situation where hosts use DHCP to obtain IP addresses. In MFF automatic mode, a VLAN can learn and maintain up to 20 gateways. The gateway IP addresses will not be updated, and the gateway information does not age out unless MFF is disabled. With MFF automatic mode enabled, a DHCP snooping device, upon receiving a DHCP ACK message, resolves Option 3 in the message (Router IP option) to obtain a gateway for the client's IP-MAC snooping entry. If the DHCP ACK message contains multiple gateway addresses, only the first one is recorded for the entry. If the message contains no gateway IP address, the first gateway recorded by the current VLAN is used. NOTE: If the source MAC address of an incoming ARP packet from a gateway is different from that of the gateway, the MFF device uses the new MAC to replace the old one. Working mechanism Hosts connecting to an MFF device use the ARP fast-reply mechanism for Layer 3 communication. This mechanism helps reduce the number of broadcast messages. The MFF device processes ARP packets in the following steps: • After receiving an ARP request from a host, the MFF device sends the MAC address of the corresponding gateway to the host. In this way, hosts in the network have to communicate at Layer 3 through a gateway. • After receiving an ARP request from a gateway, the MFF device sends the requested host's MAC address to the gateway if the corresponding entry is available; if the entry is not available, the MFF device will forward the ARP request. • The MFF device forwards ARP replies between hosts and gateways. • If the source MAC addresses of ARP requests from gateways are different from those recorded, the MFF device updates and broadcasts the IP and MAC addresses of the gateways. Protocols and standards RFC 4562, MAC-Forced Forwarding Configuring MFF Configuration prerequisites • In MFF automatic mode, enable DHCP snooping on the device and configure DHCP snooping trusted ports. • In MFF manual mode, enable ARP snooping on the device. 261

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285

261
The MFF device also forges ARP requests to get the gateway’s MAC address based on ARP snooping
entries.
After learning the gateway’s MAC address and then receiving an ARP packet with a different source
MAC address from the default gateway, the MFF device will replace the old MAC address with the new
one.
Automatic mode
The automatic mode applies to the situation where hosts use DHCP to obtain IP addresses.
In MFF automatic mode, a VLAN can learn and maintain up to 20 gateways. The gateway IP addresses
will not be updated, and the gateway information does not age out unless MFF is disabled.
With MFF automatic mode enabled, a DHCP snooping device, upon receiving a DHCP ACK message,
resolves Option 3 in the message (Router IP option) to obtain a gateway for the client’s IP-MAC snooping
entry. If the DHCP ACK message contains multiple gateway addresses, only the first one is recorded for
the entry. If the message contains no gateway IP address, the first gateway recorded by the current VLAN
is used.
NOTE:
If the source MAC address of an incoming ARP packet from a gateway is different from that of the
gateway, the MFF device uses the new MAC to replace the old one.
Working mechanism
Hosts connecting to an MFF device use the ARP fast-reply mechanism for Layer 3 communication. This
mechanism helps reduce the number of broadcast messages.
The MFF device processes ARP packets in the following steps:
After receiving an ARP request from a host, the MFF device sends the MAC address of the
corresponding gateway to the host. In this way, hosts in the network have to communicate at Layer
3 through a gateway.
After receiving an ARP request from a gateway, the MFF device sends the requested host’s MAC
address to the gateway if the corresponding entry is available; if the entry is not available, the MFF
device will forward the ARP request.
The MFF device forwards ARP replies between hosts and gateways.
If the source MAC addresses of ARP requests from gateways are different from those recorded, the
MFF device updates and broadcasts the IP and MAC addresses of the gateways.
Protocols and standards
RFC 4562,
MAC-Forced Forwarding
Configuring MFF
Configuration prerequisites
In MFF automatic mode, enable DHCP snooping on the device and configure DHCP snooping
trusted ports.
In MFF manual mode, enable ARP snooping on the device.