No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search


To have a better experience, please upgrade your IE browser.


CLI-based Configuration Guide - Ethernet Switching

AR650, AR1600, and AR6100 V300R003

This document describes how to configure the components for LAN services, including link aggregation groups, VLANs, voice VLANs, MAC address tables, transparent bridging, as well as GVRP, STP/RSTP, and MSTP protocols.
Rate and give feedback:
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
Example for Configuring MAC Address Limiting Rules on Interfaces

Example for Configuring MAC Address Limiting Rules on Interfaces

Networking Requirements

As shown in Figure 1-9, Ethernet2/0/1 and Ethernet2/0/2 of the Router are connected to LSWs. One LSW is connected to individual users, and the other is connected to enterprise users. To prevent MAC address attacks and limit the number of access users on the Router, configure MAC address limiting rules on Ethernet2/0/1 and Ethernet2/0/2.

Figure 1-9  Network diagram for MAC address limiting on interfaces

Configuration Roadmap

The configuration roadmap is as follows:

  1. Set the limit on the number of MAC addresses learned by the interfaces.

  2. Set the action performed when the limit is reached.


  1. Configure MAC address limiting rules on the interfaces.

    <Huawei> system-view
    [Huawei] interface ethernet 2/0/1
    [Huawei-Ethernet2/0/1] mac-limit maximum 4 action discard alarm enable
    [Huawei-Ethernet2/0/1] quit
    [Huawei] interface ethernet 2/0/2
    [Huawei-Ethernet2/0/2] mac-limit maximum 100 action discard alarm enable
    [Huawei-Ethernet2/0/2] quit

  2. Verify the configuration.

    # Run the display mac-limit command in any view to check whether the MAC address limiting rule is successfully configured.

    <Huawei> display mac-limit
    PORT                     VLAN      Maximum      Action      Alarm
    Eth2/0/1                 -         4            discard     enable
    Eth2/0/2                 -         100          discard     enable

Configuration Files

Configuration file of the Router

interface Ethernet2/0/1
 mac-limit maximum 4
interface Ethernet2/0/2
 mac-limit maximum 100
Updated: 2019-04-12

Document ID: EDOC1100041791

Views: 58353

Downloads: 40

Average rating:
This Document Applies to these Products
Related Version
Related Documents
Previous Next