Configuring Static Blackhole MAC Address Entries

To protect a network against attacks using MAC addresses, configure static blackhole MAC address entries to discard packets with the specified destination MAC addresses.

Usage Scenario

To prevent invalid MAC address entries, such as those of unauthorized users, from occupying a MAC address table and prevent hackers from attacking user devices or networks using MAC addresses, configure the MAC addresses of untrusted users as blackhole MAC addresses to discard packets destined for such MAC addresses.

Pre-configuration Tasks

Before configuring static blackhole MAC address entries, connect interfaces and set their physical parameters to ensure that the physical status of the interfaces is Up.

Procedure

  1. Run system-view

    The system view is displayed.

  2. Run mac-address blackhole mac-address { vlan vlan-id | vsi vsi-name }

    The static blackhole MAC address entries are configured.

  3. Run commit

    The configuration is committed.

Verifying the Configuration

Run the following commands to check the previous configurations.

  • Run the display mac-address [ mac-address ] [ vlan vlan-id | vsi vsi-name ] [ verbose ] command to check detailed information about MAC address entries.

  • Run the display mac-address blackhole [ vlan vlan-id | vsi vsi-name ] [ verbose ] command to check static blackhole MAC address entries.

Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >