Zyxel IES-1248 EE [260/544] Upstream and downstream traffic

Zyxel IES-1248 EE [260/544] Upstream and downstream traffic
Chapter 39 IP Bridge
IES-1248-51/51A/53 User’s Guide
260
In the end, the IP-aware IES-1248 makes the network more secure and more scalable, as
explained below.
User-to-user security. The IES-1248 does not forward subscribers’ MAC addresses
upstream of the IES-1248, so there is no way for subscribers to know each others MAC
addresses. This prevents the spoofing of MAC addresses and IP addresses upstream of the
IES-1248.
Scalability. The scale of access networks is typically limited by the number of MAC
addresses in the network. Since the IES-1248 does not forward subscribers’ MAC
addresses or VLAN ID upstream, the upstream network is more scalable, and it is simpler
to use the same VLAN ID upstream of several IES-1248. In addition, the IES-1248
drastically reduces the scale of ARP traffic storms.
The IES-1248 itself is transparent in the network.
39.1.1 Upstream and Downstream Traffic
When the IES-1248 forwards upstream traffic, it makes the following changes in the layer-2
header.
The original frame has the IES-1248’s MAC address as the destination MAC address because
the IES-1248, not the device that really has the destination IP, responded to the ARP request
for the destination IP. (This is part of the ARP proxy feature for IP bridges.) Once the IES-
1248 receives the frame, it updates the MAC addresses and VLAN ID and forwards it to the
device that really has the destination IP.
This is illustrated in the following example.
Table 80 IP Bridge: Layer-2 Header for Upstream Traffic
ORIGINAL UPDATED
Source MAC address Subscriber’s MAC address IES-1248’s MAC address
Destination MAC address IES-1248’s MAC address Destination IP’s MAC address
VLAN ID Subscriber’s VLAN ID Destination IP’s VLAN ID

Содержание

Скачать