Zyxel IES-5106 [657/1156] Acl antimacspoof commands

Zyxel IES-5106 [657/1156] Acl antimacspoof commands
Chapter 20 acl Commands
Management Switch Card User’s Guide
657
20.2 acl antimacspoof Commands
Use these commands to configure the Anti-MAC Spoofing feature. Anti-MAC Spoofing is a service
which detects hosts with fake or duplicated MAC addresses which attempt to access your system.
20.2.1 acl antimacspoof Command
Syntax:
acl antimacspoof show
This command shows whether the antimacspoof feature is enabled or not.
The following figure shows an example.
20.3 acl arpinspection Commands
Use these commands to configure the ARP inspection feature. ARP inspection checks ARP packets
and drops them if the MAC address to IP address binding does not match that of a learned or
manually added trusted client. This prevents many common man-in-the-middle attacks.
set <ip>/<mask>
<vid> <priority>
[<name>]
Specifies an IP address subnet for which to
configure a subnet-based VLAN.
8
show
Displays whether subnet-based VLAN is enabled
or disabled and list VLANs.
1
usbcastctrl disable
Disables rate limit for broadcast traffic. 8
enable
Enables rate limit for broadcast traffic. 8
set <rate>
Sets the maximum bandwidth for all upstream
broadcast traffic entering the MSC.
rate: 32~16384 kbps in increments of 32 kbps.
8
show
Displays rate limit settings. 1
usstorm set <slot-port>
<bcast> <mcast>
<uucast>
Sets upstream broadcast storm control limits
(from 0~148810) for the number of broadcast,
multicast, and/or unknown unicast packets the
switch receives per second on the specified
subscriber ports. -1 means no limit.
8
show <slot>|<slot-
port>
Displays the upstream broadcast storm control
limits for the specified slot or port.
1
Table 351 acl Commands (continued)
COMMAND DESCRIPTION P
ras> acl antimacspoof enable
ras> acl antimacspoof show
antimacspoof state: enable

Содержание

Скачать