Security Configuration
MAC Detection Configuration
\[Command] show mac-scan config \[Purpose] Show mac-scan configuration \[View] System View \[Use Cases] \[Command] mac-scan enable no mac-scan enable \[Purpose] Enable MAC detection function \[View] System Configuration View, VLAN View \[Comment] Enabling this feature allows sending ARP Request packets based on Snooping entries, User-bind entries, and ARP entries with corresponding IP addresses. This is often used for scenarios such as bringing dumb terminals or servers online.
ARP Detection Configuration
\[Command] show anti-attack-ckeck config \[Purpose] View ARP detection configuration \[View] System view \[Command] arp anti-attack-check {enable|trusted} no arp anti-attack-check {enable|trusted} \[Purpose] Enable ARP detection on the interface \[View] Interface View \[Usage Scenario] After enabling the ARP Snooping detection feature, the device compares the source IP, source MAC, and information from the snooping table entries and User-bind table entries for received ARP packets. If a match is found, it indicates that the user associated with the ARP packet is a legitimate user, and ARP packets from this user are permitted to pass.
SAVI Configuration
\[Command] show savi config \[Purpose] View SAVI function configuration information \[View] System view \[Command] savi enable no savi enable \[Purpose] Enable the SAVI detection function of the interface \[View] VLAN view \[Usage Scenario] After enabling SAVI function, the device will compare the source IP, source MAC, snooping table entry and User-bind table entry of the received ND protocol packets, DHCPv6 protocol packets, and if it can hit, the packets will be passed, otherwise the packets will be dropped.
IPSG Configuration
\[Command] show ipv4-source-check config \[Purpose] View the IP packet inspection function configuration information \[View] System view \[Command] show ipv6-source-check config \[Purpose] View the configuration information of IPv6 packet inspection function \[View] System view \[Command] ipv4-source-check {enable|trusted} no ipv4-source-check {enable|trusted} \[Purpose] Enable IPv4 packet inspection for physical interfaces \[View] Interface Configuration View \[Usage Scenario] When multiple VLANs are bound to an interface, enabling IPv4 source verification for trusted traffic causes all packets entering the VLAN via this interface to be trusted. \[Comment] The ipv4-source-check enable and ipv4-source-check trusted settings cannot be configured simultaneously under the interface.
IPv6 RA Guard Configuration
\[Command] show raguard policy \[Purpose] View the configuration of the RA Guard policy \[View] System view \[Command] show raguard role \[Purpose] View RA Guard interface role configuration \[View] System view \[Command] raguard role {user|router|hybrid} no raguard role {user|router|hybrid} \[Purpose] Configure the interface role for the RA Guard function \[Parameter] \[View] Interface view \[Command] raguard policy src-ip A B no raguard policy param src-ip no raguard policy \[Purpose] Configure the matching rules for the source IPv6 address of RA packets \[Parameter] \[View] VLAN view \[Command] raguard policy src-mac HH\ HH\ HH\ HH\ HH \ HH no raguard policy param src-mac no raguard policy \[Purpose] Configure the matching rules for the source MAC address of RA packets \[Parameter] \[View] VLAN view \[Command] raguard policy {hop-limit-high| hop-limit-low} value no raguard policy param {hop-limit-high| hop-limit-low} value no raguard policy \[Purpose] Configure the maximum and minimum value matching rules for the hop limit in RA packets \[Parameter] \[View] VLAN view \[Command] raguard policy managed-flag {on|off} no raguard policy param managed-flag no raguard policy \[Purpose] Configure the matching rules for the M flag bit in RA packets \[View] VLAN view \[Command] raguard policy other-flag {on|off} no raguard policy param managed-flag no raguard policy \[Purpose] Configure the matching rules for the O flag bit in RA packets \[View] VLAN view \[Command] raguard policy prefix A B/M no raguard policy param prefix no raguard policy \[Purpose] Configure the matching rules for the IPv6 prefixes carried by RA packets \[Parameter] \[View] VLAN view \[Command] raguard policy router-pref-max {low|medium|high} no raguard policy param router-pref-max no raguard policy \[Purpose] Configure the highest priority matching rule for routing RA packets \[View] VLAN view \[Usage Scenario] When an interface configured with this policy receives RA packets, it will check the routing priority carried by the packet, and RA packets with a priority less than or equal to that configured by the rule will be forwarded, otherwise they will be dropped.
User Binding Rule Configuration
\[Command] show user-bind counter \[ interface name ] clear user-bind counter \[Purpose] Show packet loss statistics for packets inspection function \[View] System view \[Notes] Statistics of packets dropped due to unhit table entries after enabling IPSG/IPSGv6/ARP detection/SAVI function. \[Command] show user-bind rule \[Purpose] View static binding table information \[View] System view \[Command] show user-bind config \[Purpose] Display packet inspection function alarms and alarm threshold related configuration \[View] System view \[Command] user-bind rule { A.
ND Snooping Configuration
\[Command] show nd snooping config \[Purpose] View ND snooping configuration \[View] System view \[Command] nd snooping enable no nd snooping enable \[Purpose] Enable ND snooping function globally \[View] System configuration view, Interface view, VLAN Interface view \[Comment] After ND Snooping is enabled on the device, the interface with ND Snooping enabled will learn the ND Snooping table entry when it receives NS packets from DAD. If the device is enabled with SAVI and IPSGv6, the ND and DHCPv6 packets will be matched according to the ND Snooping table entry.
DHCP Snooping Configuration
\[Command] show dhcp snooping config \[Purpose] View DHCP snooping related configuration status \[View] System view \[Command] show snooping table \[Purpose] View all snooping table entry details \[View] System view \[Notes] Snooping table entries include those learned by DHCP Snooping and ND Snooping. When this feature is enabled, the device can sync snooping table entries from other devices configured as neighbors, ensuring consistency across the network.
Traffic Suppression And Storm Control Configuration
\[Command] show interface storm-suppress \[Purpose] Display interface storm suppression \[View] System view \[Command] storm-suppress multicast {bytes bytes |packets packets } no storm-suppress multicast \[Purpose] Configure the maximum multicast packet traffic allowed to pass under the interface \[Parameter] \[View] Interface view \[Command] storm-suppress broadcast {bytes bytes | packets packets } no storm-suppress broadcast \[Purpose] Configure the maximum amount of broadcast packet traffic allowed to pass under the interface \[Parameter] \[View] Interface view \[Command] storm-suppress unknown {bytes bytes |packets packets } no storm-suppress unknown \[Purpose] Configure the maximum amount of unknown unicast traffic allowed to pass under the interface \[Parameter] \[View] Interface view
ACL Configuration
\[Command] show acl table \[ table name ] \[Purpose] Show existing ACL tables \[Parameter] \[View] System view \[Use Cases] \[Command] show acl rule table name rule id \[Purpose] Show existing ACL rules \[Parameter] \[View] System view \[Use Cases] \[Command] show counters acl acl table name rule id \[Purpose] Show ACL hit count \[Parameter] \[View] System view \[Comment] Allows multiple tables and rules to be entered, either as individual tables or as table + rule. Table and table are separated by ",", rule and rule are separated by ","; table and rule are separated by spaces.
Copp Speed limit
\[Command] show copp \[Purpose] View the mapping of packets types and queues \[View] System \[Usage Scenario] In a network, there are various types of packets sent to the CPU, both normal and potentially malicious. If too many packets are sent to the CPU, it can lead to high CPU utilization, performance degradation, and even system interruption.
Port Security
\[Command] show port-security \[{ethernet|link-aggregation}] \[ interface num|lag id ] \[Purpose] Display Port Security configuration \[Parameter] \[View] System view \[Command] show port-security address \[{ethernet|link-aggregation}] \[ interface num|lag id ] \[Purpose] Display specific security MAC information \[Parameter] \[View] System view \[Command] port-security enable no port-security enable \[Purpose] Enable port security function \[View] Interface view \[Comment] Before enabling port security, you need to add the interface to a VLAN first. \[Command] port-security address nn\ nn\ nn\ nn\ nn \ nn vlan vlan id no port-security address nn\ nn\ nn\ nn\ nn \ nn vlan vlan id \[Purpose] Configure static security MAC address \[View] Interface view \[Comment] Before configuring a static security MAC address, you need to enable the port security function first.