Configuring Layer 2 Port Security Features on Ethernet-Connected End Systems
This section shows how to configure the following Layer 2 port security features. For overview information about these features, see Layer 2 Port Security Features on Ethernet-Connected End Systems in Data Center Fabric Blueprint Architecture Components.
Configuring Storm Control
In this sample configuration, storm control rate limits BUM traffic on server-facing aggregated Ethernet interfaces. If the amount of BUM traffic exceeds 6% of the available bandwidth on the interface, storm control drops it to prevent broadcast storms.
To enable storm control:
Verifying Storm Control
To verify storm control activity, filter system log messages related to storm control:
user@leaf10> show log messages | match storm Sep 27 11:35:34 leaf1-qfx5100 l2ald[1923]: L2ALD_ST_CTL_IN_EFFECT: ae11.0: storm control in effect on the port
Configuring Port Security Using MAC Filtering
To configure MAC filtering, you create firewall filters in which you specify one or more of the supported match conditions. See MAC Filtering, Storm Control, and Port Mirroring Support in an EVPN-VXLAN Environment for a list of match conditions supported on QFX5110 switches and QFX10000 switches. You then apply the firewall filter to a Layer 2 interface.
To configure MAC filtering:
Verifying MAC Filtering
Configuring Analyzer-Based Port Mirroring
This section shows how to mirror ingress traffic on an underlay interface to another physical port.
The source and destination ports for mirrored traffic are on the same leaf or same spine.
Verifying Port Mirroring
To verify port mirroring:
host> show forwarding-options analyze r Analyzer name : A1 Mirror rate : 1 Maximum packet length : 0 State : up ingress monitored interfaces : ae1.0 Output interface : et-0/0/71.0
Layer 2 Port Security Features — Release History
Table 1 provides a history of all of the features in this section and their support within this reference design.
Release |
Description |
---|---|
19.1R2 |
|
18.4R2 |
QFX5120-48Y switches running Junos OS Release 18.4R2 and later releases in the same release train support all features documented in this section. |
18.1R3-S3 |
All devices in the reference design that support Junos OS Release 18.1R3-S3 and later releases in the same release train also support all features documented in this section. |