mac-limit
Syntax
mac-limit limit action action;
Hierarchy Level
[edit ethernet-switching-options secure-access-port interface (all | interface-name)]
Release Information
Statement introduced in Junos OS Release 9.0 for EX Series switches.
The default value for the action option was changed in Junos OS Release 9.5 for EX Series switches.
The shutdown option was modified in Junos OS Release 9.6 for EX Series switches.
Description
Specify the number of MAC addresses to dynamically add to the MAC address cache for this access interface (port) and the action to be taken by the switch if the MAC address learning limit is exceeded on the interface (port).
Default
The default action is drop.
Options
limit—Maximum number of MAC addresses.
action action—(Optional) Action to take when the MAC address limit is exceeded:
- drop—Drop the packet and generate an alarm, an SNMP trap, or a system log entry. This is the default.
- log—Do not drop the packet but generate an alarm, an SNMP trap, or a system log entry.
- none—No action.
- shutdown—Disable the interface and generate an alarm. If you have configured the switch with the port-error-disable statement, the disabled interface recovers automatically upon expiration of the specified disable timeout. If you have not configured the switch for autorecovery from port error disabled conditions, you can bring up the disabled interfaces by running the clear ethernet-switching port-error command.
Required Privilege Level
routing—To view this statement in the
configuration.
routing–control—To add this
statement to the configuration.
Related Topics
- allowed-mac
- Example: Configuring Port Security, with DHCP Snooping, DAI, MAC Limiting, and MAC Move Limiting, on an EX Series Switch
- Example: Configuring MAC Limiting, Including Dynamic and Allowed MAC Addresses, to Protect the Switch from Ethernet Switching Table Overflow Attacks
- Example: Configuring MAC Limiting to Protect the Switch from DHCP Starvation Attacks
- Configuring MAC Limiting (CLI Procedure)
- Configuring MAC Limiting (J-Web Procedure)
- Configuring Autorecovery From the Disabled State on Secure or Storm Control Interfaces (CLI Procedure)
