Skip to content
Ask AI

Mac-Security-Netconf

YANG Pathget/get-configedit-configrpc
/interfaces/{name}/mac-securityYmerge, replace, create, delete—
/interfaces/{name}/mac-security/mac-learning-priorityYmerge, replace, create, delete—
/interfaces/{name}/mac-security/mac-limitYmerge, replace, create, delete—
/interfaces/{name}/mac-security/port-securityYmerge, replace, create, delete—
/interfaces/{name}/mac-security/port-security/secure-addresses/{vlan-id}/{mac
-address}
Yreplace, create, delete—
/show-mac-limit——Y
/show-port-security-address——Y
clear-port-security-address——Y
show-mac-learning-group——Y
show-mac-learning-priority——Y
show-port-security——Y

This chapter provides examples on how to use Netconf to manage mac security configurations on AsterNOS devices.

Request example to get interface mac limit configuration via get-config.

<filter type="subtree">
<top>
<interfaces>
<interface>
<name>Ethernet11</name>
<mac-security>
<mac-limit/>
</mac-security>
</interface>
</interfaces>
</top>
</filter>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:2a8a97e1-ed16-4637-9e88-7814e21a1220">
<data>
<top>
<interfaces xmlns="http://asterfusion.com/ns/yang/asternos-interfaces">
<interface>
<name>Ethernet11</name>
<mac-security xmlns="http://asterfusion.com/ns/yang/asternos-mac-security">
<mac-limit>
<maximum>20</maximum>
</mac-limit>
</mac-security>
</interface>
</interfaces>
</top>
</data>
</rpc-reply>

The maximum number of MAC addresses that can be learned on the interface. The default value is 0, which means no limit. The mac-limit can’t configured on the interface which enabled mac-security. Configure mac-limit requires interface which is a vlan member.

Request example to create vlan and add interface to vlan, then configure interface mac limit via edit-config.

<config>
<top>
<vlans>
<vlan operation="create">
<vlanid>1000</vlanid>
</vlan>
</vlans>
<interfaces>
<interface>
<name>Ethernet11</name>
<vlan-config operation="create">
<vlan>
<vlan-id>1000</vlan-id>
<tagging-mode>tagged</tagging-mode>
</vlan>
</vlan-config>
</interface>
</interfaces>
</top>
</config>
<config>
<top>
<interfaces>
<interface>
<name>Ethernet11</name>
<mac-security>
<mac-limit>
<maximum>20</maximum>
</mac-limit>
</mac-security>
</interface>
</interfaces>
</top>
</config>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:a93d63b2-8c95-4480-86c8-60a431e7d6f2">
<ok/>
</rpc-reply>

Request example to delete interface mac limit via edit-config.

<config>
<top>
<interfaces>
<interface>
<name>Ethernet11</name>
<mac-security>
<mac-limit operation="delete">
</mac-limit>
</mac-security>
</interface>
</interfaces>
</top>
</config>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:eea326b0-1db3-4b43-b73b-ae658761e715">
<ok/>
</rpc-reply>

Get Interface Mac Learning Priority Configurations

Section titled “Get Interface Mac Learning Priority Configurations”

Request example to get interface mac learning priority configuration via get-config.

<filter type="subtree">
<top>
<interfaces>
<interface>
<name>Ethernet11</name>
<mac-security>
<mac-learning-priority/>
</mac-security>
</interface>
</interfaces>
</top>
</filter>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:8e756ddd-2cbf-4155-b41b-cdb79025530a">
<data>
<top>
<interfaces xmlns="http://asterfusion.com/ns/yang/asternos-interfaces">
<interface>
<name>Ethernet11</name>
<mac-security xmlns="http://asterfusion.com/ns/yang/asternos-mac-security">
<mac-learning-priority>
<priority>high</priority>
</mac-learning-priority>
</mac-security>
</interface>
</interfaces>
</top>
</data>
</rpc-reply>

Configure Mac Learning Priority On Interface

Section titled “Configure Mac Learning Priority On Interface”

The default value is low.

Request example to configure interface mac learning priority via edit-config.

<config>
<top>
<interfaces>
<interface>
<name>Ethernet11</name>
<mac-security>
<mac-learning-priority>
<priority>high</priority>
</mac-learning-priority>
</mac-security>
</interface>
</interfaces>
</top>
</config>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:b1b8232e-1edf-4f21-a5d9-c51a5c3e05d2">
<ok/>
</rpc-reply>

Request example to delete interface mac learning priority via edit-config.

<config>
<top>
<interfaces>
<interface>
<name>Ethernet11</name>
<mac-security>
<mac-learning-priority operation="delete">
</mac-learning-priority>
</mac-security>
</interface>
</interfaces>
</top>
</config>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:9fbc84a4-f30a-4c8c-8988-58fc29ae92a0">
<ok/>
</rpc-reply>

Get Interface Mac Learning Group Configurations

Section titled “Get Interface Mac Learning Group Configurations”

Request example to get interface mac learning group configuration via get-config.

<filter type="subtree">
<top>
<interfaces>
<interface>
<name>Ethernet11</name>
<mac-security>
<mac-learning-group/>
</mac-security>
</interface>
</interfaces>
</top>
</filter>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:89b6b7be-cf92-454a-ac98-9cff05a2a14b">
<data>
<top>
<interfaces xmlns="http://asterfusion.com/ns/yang/asternos-interfaces">
<interface>
<name>Ethernet11</name>
<mac-security xmlns="http://asterfusion.com/ns/yang/asternos-mac-security">
<mac-learning-group>4</mac-learning-group>
</mac-security>
</interface>
</interfaces>
</top>
</data>
</rpc-reply>

The default value is 0.

Request example to configure interface mac learning group via edit-config.

<config>
<top>
<interfaces>
<interface>
<name>Ethernet11</name>
<mac-security>
<mac-learning-group>4</mac-learning-group>
</mac-security>
</interface>
</interfaces>
</top>
</config>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:56357799-9c49-4cf8-96ef-aae3d1962c46">
<ok/>
</rpc-reply>

Request example to delete interface mac learning group via edit-config.

<config>
<top>
<interfaces>
<interface>
<name>Ethernet11</name>
<mac-security>
<mac-learning-group operation="delete">
</mac-learning-group>
</mac-security>
</interface>
</interfaces>
</top>
</config>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:9fbc84a4-f30a-4c8c-8988-58fc29ae92a0">
<ok/>
</rpc-reply>

Get Interface Port-Security Configurations

Section titled “Get Interface Port-Security Configurations”

Request example to get interface port-security configuration via get-config.

<filter type="subtree">
<top>
<interfaces>
<interface>
<name>Ethernet11</name>
<mac-security>
<port-security/>
</mac-security>
</interface>
</interfaces>
</top>
</filter>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:3113721a-11d4-4127-b723-c38de8b389ae">
<data>
<top>
<interfaces xmlns="http://asterfusion.com/ns/yang/asternos-interfaces">
<interface>
<name>Ethernet11</name>
<mac-security xmlns="http://asterfusion.com/ns/yang/asternos-mac-security">
<port-security>
<enabled>true</enabled>
<maximum>3</maximum>
<secure-addresses>
<secure-address>
<mac-address>12:34:56:78:9a:bc</mac-address>
<vlan-id>1000</vlan-id>
</secure-address>
</secure-addresses>
</port-security>
</mac-security>
</interface>
</interfaces>
</top>
</data>
</rpc-reply>

The default maximum is 1, and default violation-action is restrict. The mac-security can’t configured on the interface which mac-limit is configured. Configure mac-security requires interface which is a vlan member.

Request example to configure interface port-security via edit-config.

<config>
<top>
<interfaces>
<interface>
<name>Ethernet11</name>
<mac-security>
<port-security>
<enabled>true</enabled>
<sticky-enabled>true</sticky-enabled>
<violation-action>protect</violation-action>
<maximum>3</maximum>
</port-security>
</mac-security>
</interface>
</interfaces>
</top>
</config>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:e21e82f5-44fb-487b-8397-29ec4ab4f784">
<ok/>
</rpc-reply>

Request example to delete interface port-security via edit-config.

<config>
<top>
<interfaces>
<interface>
<name>Ethernet11</name>
<mac-security>
<port-security operation="delete">
</port-security>
</mac-security>
</interface>
</interfaces>
</top>
</config>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:8b8293cb-bfeb-4ab1-b054-b2cd9786afc0">
<ok/>
</rpc-reply>

Create static secure mac on interface requires port-security enabled on device.

Request example to configure interface port-security via edit-config.

<config>
<top>
<interfaces>
<interface>
<name>Ethernet11</name>
<mac-security>
<port-security>
<enabled>true</enabled>
<maximum>3</maximum>
<secure-addresses operation="create">
<secure-address>
<mac-address>12:34:56:78:9a:bc</mac-address>
<vlan-id>1000</vlan-id>
</secure-address>
</secure-addresses>
</port-security>
</mac-security>
</interface>
</interfaces>
</top>
</config>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:fc234ab7-0542-45c5-95ce-01bb9bcf3269">
<ok/>
</rpc-reply>

Request example to delete interface static secure mac via edit-config.

<config>
<top>
<interfaces>
<interface>
<name>Ethernet11</name>
<mac-security>
<port-security>
<secure-addresses operation="delete">
</secure-addresses>
</port-security>
</mac-security>
</interface>
</interfaces>
</top>
</config>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:c5b76a0d-3c46-4292-9b31-d70cf453afb4">
<ok/>
</rpc-reply>

Interfaces that are not displayed have a default value of 0, which means no limit.

Request example to show interface mac limit via rpc show-mac-limit.

<show-mac-limit/>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:21e9337e-f29f-4f39-9ec0-ad4e0208157f">
<data xmlns="http://asterfusion.com/ns/yang/asternos-mac-security">
Interface Mac-limit
----------- -----------
Ethernet1 0
Ethernet11 20
</data>
</rpc-reply>

Request example to show interface mac learning priority via rpc show-mac-learning-priority.

<show-mac-learning-priority/>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:9afc7076-a9ad-4c8d-b773-a843091a4d98">
<data xmlns="http://asterfusion.com/ns/yang/asternos-mac-security">
Interface Priority
--------------- ----------
Ethernet1 low
Ethernet2 low
Ethernet3 low
Ethernet4 low
Ethernet5 low
Ethernet6 low
Ethernet7 low
Ethernet8 low
Ethernet9 low
Ethernet10 low
Ethernet11 high
Ethernet12 low
Ethernet13 low
Ethernet14 low
Ethernet15 low
Ethernet16 low
Ethernet17 low
Ethernet18 low
Ethernet19 low
Ethernet20 low
Ethernet21 low
Ethernet22 low
Ethernet23 low
Ethernet24 low
Ethernet25 low
Ethernet26 low
Ethernet27 low
Ethernet28 low
Ethernet29 low
Ethernet30 low
Ethernet31 low
Ethernet32 low
Ethernet33 low
Ethernet34 low
Ethernet35 low
Ethernet36 low
Ethernet37 low
Ethernet38 low
Ethernet39 low
Ethernet40 low
Ethernet41 low
Ethernet42 low
Ethernet43 low
Ethernet44 low
Ethernet45 low
Ethernet46 low
Ethernet47 low
Ethernet48 low
Ethernet49 low
Ethernet53 low
Ethernet57 low
Ethernet61 low
Ethernet65 low
Ethernet69 low
Ethernet73 low
Ethernet77 low
PortChannel0001 low
</data>
</rpc-reply>

Request example to show interface mac learning group via rpc show-mac-learning-group.

<show-mac-learning-group/>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:3cfe03ca-8083-4305-87cc-e764976e7dcd">
<data xmlns="http://asterfusion.com/ns/yang/asternos-mac-security">
Interface Group-Id
--------------- ----------
Ethernet1 0
Ethernet2 0
Ethernet3 0
Ethernet4 0
Ethernet5 0
Ethernet6 0
Ethernet7 0
Ethernet8 0
Ethernet9 0
Ethernet10 0
Ethernet11 4
Ethernet12 0
Ethernet13 0
Ethernet14 0
Ethernet15 0
Ethernet16 0
Ethernet17 0
Ethernet18 0
Ethernet19 0
Ethernet20 0
Ethernet21 0
Ethernet22 0
Ethernet23 0
Ethernet24 0
Ethernet25 0
Ethernet26 0
Ethernet27 0
Ethernet28 0
Ethernet29 0
Ethernet30 0
Ethernet31 0
Ethernet32 0
Ethernet33 0
Ethernet34 0
Ethernet35 0
Ethernet36 0
Ethernet37 0
Ethernet38 0
Ethernet39 0
Ethernet40 0
Ethernet41 0
Ethernet42 0
Ethernet43 0
Ethernet44 0
Ethernet45 0
Ethernet46 0
Ethernet47 0
Ethernet48 0
Ethernet49 0
Ethernet53 0
Ethernet57 0
Ethernet61 0
Ethernet65 0
Ethernet69 0
Ethernet73 0
Ethernet77 0
PortChannel0001 0
</data>
</rpc-reply>

Request example to show interface mac port security via rpc show-port-security.

<show-port-security/>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:db3c9b93-7cee-4235-a410-3b85328eb4fa">
<data xmlns="http://asterfusion.com/ns/yang/asternos-mac-security">
Interface Port-Security Sticky-Mac Max-Secure-Addr Violation-Action
----------- --------------- ------------ ----------------- ------------------
Ethernet11 enable disable 3 restrict
</data>
</rpc-reply>

Both static and dynamic learned Secure MAC addresses will be retrieved.

Request example to show interface mac port security addresses via rpc show-port-security-address.

<show-port-security-address/>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:b59ae792-b2f8-4ce9-a17a-783b2688bf3f">
<data>
<mac-address-info>
<vlan-id>Vlan1000</vlan-id>
<mac-address>12:34:56:78:9a:bc</mac-address>
<type>static</type>
<port>Ethernet11</port>
<index>1</index>
</mac-address-info>
<mac-address-info>
<vlan-id>Vlan10</vlan-id>
<mac-address>60:eb:5a:01:1c:e4</mac-address>
<type>dynamic</type>
<port>Ethernet1</port>
<index>2</index>
</mac-address-info>
</data>
</rpc-reply>

Both static and dynamic learned Secure MAC addresses will be deleted.

Request example to clear interface mac port security addresses via rpc clear-port-security-address.

<clear-port-security-address/>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:a9cdd8de-9722-41f9-911f-297301d36a7e">
<data xmlns="http://asterfusion.com/ns/yang/asternos-mac-security">
success
</data>
</rpc-reply>

Request example to clear interface mac port security addresses via rpc clear-port-security-address.

<clear-port-security-address>
<interface>Ethernet11</interface>
</clear-port-security-address>

Response example

<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:5c9a8281-8e6a-44bd-938f-55987af27e75">
<data xmlns="http://asterfusion.com/ns/yang/asternos-mac-security">
success
</data>
</rpc-reply>

Tree Diagram

module: asternos-mac-security
augment /if:interfaces/if:interface:
+--rw mac-security

Tree Diagram

module: asternos-mac-security
augment /if:interfaces/if:interface:
+--rw mac-security

Tree Diagram

module: asternos-mac-security
augment /if:interfaces/if:interface:
+--rw mac-security

Tree Diagram

module: asternos-mac-security
augment /if:interfaces/if:interface:
+--rw mac-security

Tree Diagram

module: asternos-mac-security
augment /if:interfaces/if:interface:
+--rw mac-security

Tree Diagram

module: asternos-mac-security
augment /if:interfaces/if:interface:
+--rw mac-security
rpcs:
+---x show-mac-limit
+---w input
| +---w (filter)
| +--:(port-name)
| | +---w port-name? cmn:ethernet-port-name
| +--:(portchannel-name)
| | +---w portchannel-name? cmn:port-channel-name
| +--:(vlan-id)
| | +---w vlan-id? cmn:vlan-id
| +--:(all)
| +---w all? empty
+--ro output
+--ro data? <anydata>

Table of Properties

NameRequiredType/RangeDescription
show-mac-limitO
port-nameOcmn:ethernet-port-nameName of the Ethernet interface.
portchannel-nameOcmn:port-channel-nameName of the portchannel interface.
vlan-idOcmn:vlan-idVLAN ID
allOemptyshow all mac limit
dataOA table that shows MAC address learning limit information

Tree Diagram

module: asternos-mac-security
augment /if:interfaces/if:interface:
+--rw mac-security
rpcs:
+---x show-port-security-address
+---w input
| +---w interface? union
+--ro output
+--ro data? <anydata>

Table of Properties

NameRequiredType/RangeDescription
show-port-security-addressO
interfaceOEthernet nameName of the Ethernet or PortChannel (empty for all interfaces).
dataOshow secure mac addresses

Tree Diagram

module: asternos-mac-security
augment /if:interfaces/if:interface:
+--rw mac-security
rpcs:
+---x clear-port-security-address
+---w input
| +---w interface? union
| +---w fdb-type? enumeration
+--ro output
+--ro data? <anydata>

Table of Properties

NameRequiredType/RangeDescription
clear-port-security-addressO
interfaceOEthernet nameName of the Ethernet or PortChannel (empty for all interfaces).
fdb-typeO”static"
"dynamic"
"sticky"
"all”
The type of fdb to clear (empty for all types).
dataOThe string indicates success or failure of this operation

Tree Diagram

module: asternos-mac-security
augment /if:interfaces/if:interface:
+--rw mac-security
rpcs:
+---x show-mac-learning-group
+---w input
| +---w interface? union
+--ro output
+--ro data? <anydata>

Table of Properties

NameRequiredType/RangeDescription
show-mac-learning-groupO
interfaceOEthernet nameName of the Ethernet or PortChannel (empty for all interfaces)
dataOshow port mac learning group id configurations

Tree Diagram

module: asternos-mac-security
augment /if:interfaces/if:interface:
+--rw mac-security
rpcs:
+---x show-mac-learning-priority
+---w input
| +---w interface? union
+--ro output
+--ro data? <anydata>

Table of Properties

NameRequiredType/RangeDescription
show-mac-learning-priorityO
interfaceOEthernet nameName of the Ethernet or PortChannel (empty for all interfaces)
dataOshow port mac learning priority configurations

Tree Diagram

module: asternos-mac-security
augment /if:interfaces/if:interface:
+--rw mac-security
rpcs:
+---x show-port-security
+---w input
| +---w interface? union
+--ro output
+--ro data? <anydata>

Table of Properties

NameRequiredType/RangeDescription
show-port-securityO
interfaceOEthernet nameName of the Ethernet or PortChannel (empty for all interfaces)
dataOshow port security configurations