H3C Low-End and Mid-Range Ethernet Switches Configuration Examples(V1.01)

HomeSupportSwitchesH3C S5500 Switch SeriesConfigure & DeployConfiguration ExamplesH3C Low-End and Mid-Range Ethernet Switches Configuration Examples(V1.01)
Table of Contents
Related Documents
09-MAC Address Table Management Configuration Guide

Configuring MAC Address Table Management

Network Diagram

Figure 1-1 Network diagram for MAC address table management

 

Networking and Configuration Requirements

Server is connected to Switch through port GigabitEthernet 1/0/2. Configure a static MAC address entry of Server on Switch, so that Switch always unicasts rather than broadcasts packets destined for Server through GigabitEthernet 1/0/2. Port GigabitEthernet 1/0/10 is connected with a network management server (NMS). For network management security, configure GigabitEthernet 1/0/10 to permit the access of this NMS only.

l          The MAC address of Server is 000f-e20f-dc71

l          Port GigabitEthernet 1/0/2, GigabitEthernet 1/0/5, and GigabitEthernet 1/0/10 belong to VLAN 10

l          The MAC address of NMS is 0014-222c-aa69

l          Set the aging time of MAC address entries on Switch to 500 seconds

Applicable Product Matrix

Product series

Software version

Hardware version

S3610 Series Ethernet Switches

Release 5301, Release 5303

All versions

S5510 Series Ethernet Switches

Release 5301, Release 5303

All versions

S5500-SI Series Ethernet Switches

Release 1207

All versions except S5500-20TP-SI

Release 1301

S5500-20TP-SI

S5500-EI Series Ethernet Switches

Release 2102

All versions

S7500E Series Ethernet Switches

Release 6100, Release 6300

All versions

 

Configuration Procedure

# Create VLAN 10, and add ports GigabitEthernet 1/0/2, GigabitEthernet 1/0/5, and GigabitEthernet 1/0/10 to VLAN 10.

<Sysname> system-view

[Sysname] vlan 10

[Sysname-vlan10] port GigabitEthernet1/0/2 GigabitEthernet1/0/5 GigabitEthernet1/0/10

# Add a static MAC address entry.

[Sysname] mac-address static 000f-e20f-dc71 interface GigabitEthernet 1/0/2 vlan 10

# Set the aging time of dynamic MAC address entries on Switch to 500 seconds.

[Sysname] mac-address timer aging 500

# Display the configuration of MAC address table in system view.

[Sysname] display mac-address interface GigabitEthernet 1/0/2

MAC ADDR          VLAN ID   STATE            PORT INDEX              AGING TIME(s)

000f-e20f-dc71  1          Config static  GigabitEthernet1/0/2  NOAGED

00e0-fc17-a7d6  1          Learned         GigabitEthernet1/0/2  AGING

00e0-fc5e-b1fb  1          Learned         GigabitEthernet1/0/2  AGING

00e0-fc55-f116  1          Learned         GigabitEthernet1/0/2  AGING

---  4 mac address(es) found on port GigabitEthernet1/0/2 ---

# Set the MAC learning limit to 0 on GigabitEthernet 1/0/10, and add a static MAC address entry for the port, so that port GigabitEthernet 1/0/10 can forward only the packets sent by NMS, and other hosts cannot communicate through this port.

[Sysname] interface GigabitEthernet 1/0/10

[Sysname-GigabitEthernet1/0/10] port access vlan 10

[Sysname-GigabitEthernet1/0/10] mac-address max-mac-count 0

[Sysname-GigabitEthernet1/0/10] mac-address static 0014-222c-aa69 vlan 10

# Disable GigabitEthernet 1/0/10 from forward frames whose source MAC addresses are not in the MAC address table when the MAC learning limit is reached. Ethernet switches of the S3610, S5510, and S3500-EA series support this operation.

[Sysname-GigabitEthernet1/0/10] mac-address max-mac-count disable-forwarding

Complete Configuration

#

 mac-address timer aging 500

#

vlan 10

#

interface GigabitEthernet1/0/2

 port access vlan 10

 mac-address static 000f-e20f-dc71 vlan 10

#

interface GigabitEthernet1/0/5  

 port access vlan 10

#

interface GigabitEthernet1/0/10

 port access vlan 10

 mac-address max-mac-count 0

 mac-address max-mac-count disable-forwarding

 mac-address static 0014-222c-aa69 vlan 10

Configuration Guidelines

l          You cannot configure a static or dynamic MAC address entry on an aggregate port of any device of any version, except for Release 6300 of the S7500 series Ethernet switches.

l          The MAC address aging timer setting takes effect on all ports. It affects only dynamic MAC address entries including those learned by the device and manually configured as dynamic entries.

l          Ethernet switches of the S5500-SI, S5500-EI, and S7500E series do not support the disable-forwarding keyword in the mac-address max-mac-count command. When the MAC learning limit is reached, the port does not forward frames whose source MAC addresses are not in the MAC address table.

  • Cloud & AI
  • InterConnect
  • Intelligent Computing
  • Security
  • SMB Products
  • Intelligent Terminal Products
  • Product Support Services
  • Technical Service Solutions
All Services
  • Resource Center
  • Policy
  • Online Help
All Support
  • Become a Partner
  • Partner Resources
  • Partner Business Management
All Partners
  • Profile
  • News & Events
  • Online Exhibition Center
  • Contact Us
All About Us
新华三官网