XGS-5240-Series User Manual

Table Of Contents
Configuration Guide of XGS-5240-Series
48-2
f MAC address on each port and the number of ARP, ND on each INTERFACE VLAN.
The number of static or dynamic MAC address on a port should not exceed the confi
guration. The number of user on each VLAN should not exceed the configuration, eithe
r.
Limiting the number of MAC and ARP list entry can avoid DOS attack to a certain
extent. When malicious users frequently do MAC or ARP cheating, it will be easy for t
hem to fill the MAC and ARP list entries of the switch, causing successful DOS attack
s.
To summer up, it is very meaningful to develop the number limitation function of M
AC and IP in port, VLAN. Switch can control the number of MAC address of ports and
the number ARP, ND list entry of ports and VLAN through configuration commands.
Limiting the number of dynamic MAC and IP of ports:
1. Limiting the number of dynamic MAC. If the number of dynamically learnt MAC
address by the switch is already larger than or equal with the max number of dynamic
MAC address, then shutdown the MAC study function on this port, otherwise, the port
can continue its study.
2. Limiting the number of dynamic IP. If the number of dynamically learnt ARP and
ND by the switch is already larger than or equal with the max number of dynamic AR
P and ND, then shutdown the ARP and ND study function of this port, otherwise, the
port can continue its study.
Limiting the number of MAC, ARP and ND of interfaces:
1. Limiting the number of dynamic MAC. If the number of dynamically learnt MAC
address by the VLAN of the switch is already larger than or equal with the max numb
er of dynamic MAC address, then shutdown the MAC study function of all the ports in
this VLAN, otherwise, all the ports in this VLAN can continue their study (except specia
l ports).
2. Limiting the number of dynamic IP. If the number of dynamically learnt ARP and
ND by the switch is already larger than or equal with the max number of dynamic AR
P and ND, then the VLAN will not study any new ARP or ND, otherwise, the study ca
n be continued.
48.2 The Number Limitation Function of MAC and I
P in Port, VLAN Configuration Task Sequence
1. Enable the number limitation function of MAC and IP on ports
2. Enable the number limitation function of MAC and IP in VLAN
3. Configure the timeout value of querying dynamic MAC