Defining mac address filters, Supported mac address filter features – Brocade FastIron Ethernet Switch Security Configuration Guide User Manual

Page 247

Advertising
background image

Defining MAC Address Filters

Supported MAC address filter features......................................................................... 247

MAC address filters configuration notes and limitations............................................... 247

MAC address filters command syntax...........................................................................248

Enabling logging of management traffic permitted by MAC address filters...................249

Configuring MAC filter accounting.................................................................................250

MAC address filter override for 802.1X-enabled ports.................................................. 251

Supported MAC address filter features

Lists MAC address filter features supported on FastIron devices.

The following table lists individual Brocade switches and the MAC address filter features they support.

Feature

ICX 6430

ICX 6450

FCX

ICX 6610

ICX 6650

FSX 800
FSX 1600

ICX 7750

MAC accounting

No

08.0.10a

08.0.10a

08.0.10a

08.0.10a

08.0.10a

08.0.10a

MAC address filtering

08.0.01

08.0.01

08.0.01

08.0.01

08.0.01

08.0.01

08.0.10

MAC address filter override of 802.1X

08.0.01

08.0.01

08.0.01

08.0.01

No

08.0.01

No

MAC address filters configuration notes and limitations

• MAC address filtering on FastIron devices is performed in hardware.
• MAC address filtering on FastIron devices differ from other Brocade devices in that you can only filter

on source and destination MAC addresses. Other Brocade devices allow you to also filter on the
encapsulation type and frame type.

• MAC address filtering applies to all traffic, including management traffic. To exclude management

traffic from being filtered, configure a MAC address filter that explicitly permits all traffic headed to the
management MAC (destination) address. The MAC address for management traffic is always the
MAC address of port 1.

• MAC address filters that have a global deny statement can cause the device to block all BPDUs. In

this case, include exception statements for control protocols in the MAC address filter configuration.

• MAC address filtering cannot be applied on management interface for all platforms.

The following configuration notes apply to Brocade Layer 3 devices:

• MAC address filters apply to both switched and routed traffic. If a routing protocol (for example,

OSPF) is configured on an interface, the configuration must include a MAC address filter rule that
allows the routing protocol MAC and the neighbor system MAC address.

• You cannot use MAC address filters to filter Layer 4 information.
• MAC address filters are supported on tagged ports in the Layer 3 software images.

FastIron Ethernet Switch Security Configuration Guide

247

53-1003088-03

Advertising