21.03.2013 Views

Junos® OS Ethernet Interfaces Configuration ... - Juniper Networks

Junos® OS Ethernet Interfaces Configuration ... - Juniper Networks

Junos® OS Ethernet Interfaces Configuration ... - Juniper Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

CHAPTER 11<br />

Configuring MAC Address Validation on<br />

Static <strong>Ethernet</strong> <strong>Interfaces</strong><br />

• MAC Address Validation on Static <strong>Ethernet</strong> <strong>Interfaces</strong> Overview on page 173<br />

• Configuring MAC Address Validation on Static <strong>Ethernet</strong> <strong>Interfaces</strong> on page 174<br />

• Disabling MAC Address Learning of Neighbors Through ARP or Neighbor Discovery for<br />

IPv4 and IPv6 Neighbors on page 174<br />

MAC Address Validation on Static <strong>Ethernet</strong> <strong>Interfaces</strong> Overview<br />

Related<br />

Documentation<br />

Copyright © 2012, <strong>Juniper</strong> <strong>Networks</strong>, Inc.<br />

MAC address validation enables the router to validate that received packets contain a<br />

trusted IP source and an <strong>Ethernet</strong> MAC source address.<br />

MAC address validation is supported on AE, Fast <strong>Ethernet</strong>, Gigabit <strong>Ethernet</strong>, and 10–Gigabit<br />

<strong>Ethernet</strong> interfaces (with or without VLAN tagging) on MX Series routers only.<br />

There are two types of MAC address validation that you can configure:<br />

• Loose—Forwards packets when both the IP source address and the MAC source address<br />

match one of the trusted address tuples.<br />

Drops packets when the IP source address matches one of the trusted tuples, but the<br />

MAC address does not support the MAC address of the tuple<br />

Continues to forward packets when the source address of the incoming packet does<br />

not match any of the trusted IP addresses.<br />

• Strict—Forwards packets when both the IP source address and the MAC source address<br />

•<br />

match one of the trusted address tuples.<br />

Drops packets when the MAC address does not match the tuple's MAC source address,<br />

or when IP source address of the incoming packet does not match any of the trusted<br />

IP addresses.<br />

Configuring MAC Address Validation on Static <strong>Ethernet</strong> <strong>Interfaces</strong> on page 174<br />

• Disabling MAC Address Learning of Neighbors Through ARP or Neighbor Discovery for<br />

IPv4 and IPv6 Neighbors on page 174<br />

• <strong>Junos®</strong> <strong>OS</strong> <strong>Ethernet</strong> <strong>Interfaces</strong><br />

173

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!