Brocade FastIron Ethernet Switch Security Configuration Gu Manual de usuario Pagina 247

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 396
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 246
Defining MAC Address Filters
Supported MAC address filter features......................................................................... 247
MAC address filters configuration notes and limitations............................................... 247
MAC address filters command syntax...........................................................................248
Enabling logging of management traffic permitted by MAC address filters...................249
Configuring MAC filter accounting.................................................................................250
MAC address filter override for 802.1X-enabled ports.................................................. 251
Supported MAC address filter features
Lists MAC address filter features supported on FastIron devices.
The following table lists individual Brocade switches and the MAC address filter features they support.
Feature ICX 6430 ICX 6450 FCX ICX 6610 ICX 6650 FSX 800
FSX 1600
ICX 7750
MAC accounting No 08.0.10a 08.0.10a 08.0.10a 08.0.10a 08.0.10a 08.0.10a
MAC address filtering 08.0.01 08.0.01 08.0.01 08.0.01 08.0.01 08.0.01 08.0.10
MAC address filter override of 802.1X 08.0.01 08.0.01 08.0.01 08.0.01 No 08.0.01 No
MAC address filters configuration notes and limitations
MAC address filtering on FastIron devices is performed in hardware.
MAC address filtering on FastIron devices differ from other Brocade devices in that you can only filter
on source and destination MAC addresses. Other Brocade devices allow you to also filter on the
encapsulation type and frame type.
MAC address filtering applies to all traffic, including management traffic. To exclude management
traffic from being filtered, configure a MAC address filter that explicitly permits all traffic headed to the
management MAC (destination) address. The MAC address for management traffic is always the
MAC address of port 1.
MAC address filters that have a global deny statement can cause the device to block all BPDUs. In
this case, include exception statements for control protocols in the MAC address filter configuration.
MAC address filtering cannot be applied on management interface for all platforms.
The following configuration notes apply to Brocade Layer 3 devices:
MAC address filters apply to both switched and routed traffic. If a routing protocol (for example,
OSPF) is configured on an interface, the configuration must include a MAC address filter rule that
allows the routing protocol MAC and the neighbor system MAC address.
You cannot use MAC address filters to filter Layer 4 information.
MAC address filters are supported on tagged ports in the Layer 3 software images.
FastIron Ethernet Switch Security Configuration Guide
247
53-1003088-03
Vista de pagina 246
1 2 ... 242 243 244 245 246 247 248 249 250 251 252 ... 395 396

Comentarios a estos manuales

Sin comentarios