To do…

 

Use the command…

 

Remarks

 

 

 

Set the maximum number of

 

 

 

Required

 

 

 

 

mac-address

 

By default, the number of the

 

 

 

MAC addresses the port can

 

 

 

 

 

 

max-mac-count count

 

MAC addresses a port can learn

 

 

 

learn

 

 

 

 

 

 

 

 

is not limited.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Specifying the maximum number of MAC addresses a port can learn disables centralized MAC address authentication and port security on the port. On the other hand, if you enable centralized MAC address authentication and port security on a port, you cannot specify the maximum number of MAC addresses the port can learn.

Disabling MAC Address learning for a VLAN

You can disable a switch from learning MAC addresses in specific VLANs to improve stability and security for the users belong to these VLANs and prevent unauthorized accesses.

Follow these steps to disable MAC address learning for a VLAN:

 

 

To do…

 

Use the command…

 

Remarks

 

 

 

Enter system view

 

system-view

 

 

 

 

 

 

 

 

 

 

 

 

Enter VLAN view

 

vlan vlan-id

 

 

 

 

 

 

 

 

 

 

 

 

Disable the switch from learning

 

mac-address

 

Required

 

 

 

 

 

By default, the device learns

 

 

 

MAC addresses in the VLAN

 

max-mac-count 0

 

 

 

 

 

 

MAC addresses in every VLAN.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

z

z

If the VLAN is configured as a remote probe VLAN used by port mirroring, you can not disable MAC address learning of this VLAN. Similarly, after you disable MAC address learning, this VLAN can not be configured as a remote probe VLAN.

Disabling the MAC address learning function of a VLAN takes no effect on enabling the centralized MAC address authentication on the ports that belong to the VLAN.

1-7

Page 167
Image 167
3Com WX3000 operation manual Disabling MAC Address learning for a Vlan, Mac-address, Max-mac-count count