Netgear XCM8810 Chassis Hardware Installation Guide - Page 575
Stop learning, Port lockdown, Example
View all Netgear XCM8810 Chassis manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 575 highlights
NETGEAR 8800 Chassis Switch CLI Manual Stop learning When stop-learning is enabled with learning-limit configured, the switch is protected from exhausting FDB resources by not creating blackhole entries. Any additional learning and forwarding is prevented, but packet forwarding from FDB entries is not impacted. Port lockdown The port lockdown feature allows you to prevent any additional learning on the virtual port, keeping existing learned entries intact. This is equivalent to making the dynamically-learned entries permanent static, and setting the learning limit to zero. All new source MAC addresses are blackholed. Locked entries do not get aged, but can be deleted like any other permanent FDB entries. The maximum number of permanent lockdown entries is 1024. Any FDB entries above will be flushed and blackholed during lockdown. For ports that have lockdown in effect, the following traffic still flows to the port: • Packets destined for the permanent MAC and other non-blackholed MACs • Broadcast traffic Traffic from the permanent MAC will still flow from the virtual port. Once the port is locked down, all the entries become permanent and will be saved across reboot. When you remove the lockdown using the unlock-learning option, the learning-limit is reset to unlimited, and all associated entries in the FDB are flushed. To display the locked entries on the switch, use the following command: show fdb Locked MAC address entries have the "l" flag. To verify the MAC security configuration for the specified VLAN or ports, use the following commands: show vlan security show ports info detail Example The following command limits the number of MAC addresses that can be learned on ports 1, 2, 3, and 6 in a VLAN named accounting, to 128 addresses: configure ports 1, 2, 3, 6 vlan accounting learning-limit 128 The following command locks ports 4 and 5 of VLAN accounting, converting any FDB entries to static entries, and prevents any additional address learning on these ports: configure ports 4,5 vlan accounting lock-learning The following command removes the learning limit from the specified ports: configure ports 1, 2, vlan accounting unlimited-learning Chapter 15. Security Commands | 575