Disabling an Interface from Broadcasting Packets to Other Interfaces in a Bridge Domain

You can disable an EVC Layer 2 sub-interface from broadcasting packets to other EVC Layer 2 sub-interfaces in a bridge domain. This function helps devices from being attacked and improves network security.

Context

An EVC Layer 2 sub-interface can be disabled from broadcasting received broadcast packets, unknown unicast packets, and unknown multicast packets to other EVC Layer 2 sub-interfaces in the same bridge domain.

Forwarding malicious unknown unicast packets increases device resource consumption. As a result, device performance deteriorates, or a device breaks down. Preventing an EVC Layer 2 sub-interface from broadcasting received packets to other EVC Layer 2 sub-interfaces in the same bridge domain prevents attacks initiated using unknown packets.

This function applies to networks without user changes or networks with static MAC address-based forwarding paths.

Procedure

  1. Run system-view

    The system view is displayed.

  2. Run bridge-domain bd-id

    The bridge domain view is displayed.

  3. Perform one of the following steps to disable an interface from broadcasting packets to other interfaces in a bridge domain:

    • To disable an interface from broadcasting packets to other interfaces in a bridge domain, run the broadcast discard command.
    • To disable an interface from forwarding unknown unicast packets to other interfaces in a bridge domain, run the unknown-unicast discard command.
    • To disable an interface from forwarding multicast packets to other interfaces in a bridge domain, run the unknown-multicast discard command.

  4. Run commit

    The configuration is committed.

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
Next topic >