[f-nsp] MAC security per VLAN

Alexander Shikoff minotaur at crete.org.ua
Mon Jul 16 19:30:51 EDT 2012


Hello!

I have some customer's connections to my MLXe box. All its ports are
switched, and there are some tagged VLANs in them. 

I need to disable MAC learning only in one VLAN, in other VLANs MAC
learning should be enabled without any limits.

In 'port security' configuration section of interface I can set up
static MAC addresses in certain VLAN, but I cannot disable MAC learning 
per VLAN: 'dynamic-learn' command does not have VLAN parameter.

Is there a way to achieve this? Thanks in advance!

P.S. Please don't blame me for mention of rival but in Extreme XOS
it can be done very easily with two commands:
# configure port X vlan Test limit-learning 0
# create fdbentry 00:11:12:13:14:15 vlan Test port X

-- 
MINO-RIPE


More information about the foundry-nsp mailing list