Zyxel VES-1616FE-55A [239/318] Hapter

Zyxel VES-1616FE-55A [239/318] Hapter
VES-1616FE-55A User’s Guide
239
CHAPTER 43
MAC Force Forwarding
43.1 Overview
MAC force forwarding is a method used to separate subscribers for management purposes.
The VES-1616FE-55A intercepts a subscribers ARP (Address Resolution Protocol) requests
and has the subscriber send traffic to a pre-defined Access Router (AR) or Application Server
(AS). The AR or AS routes or forwards subscriber traffic so the subscribers do not know the
MAC addresses of servers on the network. A network administrator can use the AR or AS to
monitor and manage subscriber traffic. This prevents attackers from getting MAC address
information from your network and improves the network bandwidth usage performance.
An example is shown next, MAC force forwarding is disabled at the left. A is a subscriber who
sends an ARP request to ask a servers (S) MAC address. All subscribers, router (AR), and S
receive a copy from the VES-1616FE-55A (D). S then replies to A’s request. A and S
communicate directly for further data transmission. In this case, all subscribers in the network
can know the servers’ MAC address information.
However, with MAC force forwarding enabled (as shown next at the right), D will reply to A’s
ARP request with ARs MAC address. A sends traffic to AR. AR forwards the traffic to S. In
this case, none of the subscribers can know Ss MAC address.
Figure 140 MAC Force Forwarding
AB
C
AR
S
D
AB
C
AR
S
D
Without MAC Force Forwarding With MAC Force Forwarding

Содержание

Скачать