Configuring network port, Configuration prerequisites – H3C Technologies H3C S3600 Series Switches User Manual
Page 627
5-6
Operation
Command
Remarks
Enter Ethernet port view
interface interface-type
interface-number
—
Enable IP filtering on the port
ip check source ip-address
[ mac-address ]
Required
Disabled by default
Add the port to the isolation
group
port isolate
Required
By default, an Ethernet port is
not added to any isolation
group.
Configure the port as an MFF
user port
arp mac-forced-forwarding
user-port
Required
No user port configured by
default
z
On a port configured as an MFF user port or MFF network port, aggregation synchronization will
not occur. To ensure proper MFF implementation, you need to perform manual configurations to
ensure that all the ports in an aggregation group are MFF user ports or MFF network ports.
z
If several access-layer switches are connected in series in the network and multiple VLANs are
created on the downstream switches, to ensure proper MFF operation, the downstream user port
on the upstream switch must be configured as an ARP trusted port.
Configuring Network Port
Configuration prerequisites
Before configuring a port as the MFF network port on an access-layer switch, enable DHCP snooping
on the switch and verify the following:
z
ARP intrusion detection is enabled in the VLAN to which the port belongs.
z
The port is configured as an ARP intrusion detection trusted port and a DHCP snooping trusted
port.
In case multiple access-layer switches are connected in series in the actual networking environment, if
a downstream port of the upstream access-layer switch is an MFF network port, the port cannot be
configured as a DHCP snooping trusted port.