< Home

(Optional) Configuring MFF to Be Enabled When Receiving ARP Packets

Context

In a data center, users and virtual machine (VM) servers are isolated at Layer 2 on EAN devices using MFF. If a VM connects to another EAN after migrating between servers, the backup binding table may exist on the new EAN after the migration, and the original EAN device may continue to reserve the original MFF entries. This situation cannot ensure the effectiveness of Layer 2 isolation or the level of security in Layer 3 communication between users and servers. To address this problem, configure MFF to be enabled upon receiving ARP packets.

Procedure

  1. Run system-view

    The system view is displayed.

  2. Run vlan vlan-id

    The VLAN view is displayed.

  3. Run mac-forced-forwarding arp-trigger

    The EAN is configured to add or update the MFF entries when receiving an ARP packet from a user.

    By default, the EAN does not add or update an MFF entry when receiving an ARP packet from a user.

  4. Run mac-forced-forwarding network-port-arp-trigger

    The EAN is configured to delete the MFF entry when a network interface receives an ARP packet.

    By default, the network interface on an EAN does not delete the MFF entry when receiving an ARP packet.

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >