Mac-Security-Netconf
此内容尚不支持你的语言。
Mac Security
Section titled “Mac Security”Resources Summary
Section titled “Resources Summary”| YANG Path | get/get-config | edit-config | rpc |
|---|---|---|---|
| /interfaces/{name}/mac-security | Y | merge, replace, create, delete | — |
| /interfaces/{name}/mac-security/mac-learning-priority | Y | merge, replace, create, delete | — |
| /interfaces/{name}/mac-security/mac-limit | Y | merge, replace, create, delete | — |
| /interfaces/{name}/mac-security/port-security | Y | merge, replace, create, delete | — |
| /interfaces/{name}/mac-security/port-security/secure-addresses/{vlan-id}/{mac -address} | Y | replace, create, delete | — |
| /show-mac-limit | — | — | Y |
| /show-port-security-address | — | — | Y |
| clear-port-security-address | — | — | Y |
| show-mac-learning-group | — | — | Y |
| show-mac-learning-priority | — | — | Y |
| show-port-security | — | — | Y |
Examples
Section titled “Examples”This chapter provides examples on how to use Netconf to manage mac security configurations on AsterNOS devices.
Get Interface Mac Limit Configurations
Section titled “Get Interface Mac Limit Configurations”Request example to get interface mac limit configuration via get-config.
<filter type="subtree"> <top> <interfaces> <interface> <name>Ethernet11</name> <mac-security> <mac-limit/> </mac-security> </interface> </interfaces> </top></filter>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:2a8a97e1-ed16-4637-9e88-7814e21a1220"> <data> <top> <interfaces xmlns="http://asterfusion.com/ns/yang/asternos-interfaces"> <interface> <name>Ethernet11</name> <mac-security xmlns="http://asterfusion.com/ns/yang/asternos-mac-security"> <mac-limit> <maximum>20</maximum> </mac-limit> </mac-security> </interface> </interfaces> </top> </data></rpc-reply>Configure Mac Limit On Interface
Section titled “Configure Mac Limit On Interface”The maximum number of MAC addresses that can be learned on the interface. The default value is 0, which means no limit. The mac-limit can’t configured on the interface which enabled mac-security. Configure mac-limit requires interface which is a vlan member.
Request example to create vlan and add interface to vlan, then configure interface mac limit via edit-config.
<config> <top> <vlans> <vlan operation="create"> <vlanid>1000</vlanid> </vlan> </vlans> <interfaces> <interface> <name>Ethernet11</name> <vlan-config operation="create"> <vlan> <vlan-id>1000</vlan-id> <tagging-mode>tagged</tagging-mode> </vlan> </vlan-config> </interface> </interfaces> </top></config>
<config> <top> <interfaces> <interface> <name>Ethernet11</name> <mac-security> <mac-limit> <maximum>20</maximum> </mac-limit> </mac-security> </interface> </interfaces> </top></config>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:a93d63b2-8c95-4480-86c8-60a431e7d6f2"> <ok/></rpc-reply>Delete Mac Limit On Interface
Section titled “Delete Mac Limit On Interface”Request example to delete interface mac limit via edit-config.
<config> <top> <interfaces> <interface> <name>Ethernet11</name> <mac-security> <mac-limit operation="delete"> </mac-limit> </mac-security> </interface> </interfaces> </top></config>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:eea326b0-1db3-4b43-b73b-ae658761e715"> <ok/></rpc-reply>Get Interface Mac Learning Priority Configurations
Section titled “Get Interface Mac Learning Priority Configurations”Request example to get interface mac learning priority configuration via get-config.
<filter type="subtree"> <top> <interfaces> <interface> <name>Ethernet11</name> <mac-security> <mac-learning-priority/> </mac-security> </interface> </interfaces> </top></filter>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:8e756ddd-2cbf-4155-b41b-cdb79025530a"> <data> <top> <interfaces xmlns="http://asterfusion.com/ns/yang/asternos-interfaces"> <interface> <name>Ethernet11</name> <mac-security xmlns="http://asterfusion.com/ns/yang/asternos-mac-security"> <mac-learning-priority> <priority>high</priority> </mac-learning-priority> </mac-security> </interface> </interfaces> </top> </data></rpc-reply>Configure Mac Learning Priority On Interface
Section titled “Configure Mac Learning Priority On Interface”The default value is low.
Request example to configure interface mac learning priority via edit-config.
<config> <top> <interfaces> <interface> <name>Ethernet11</name> <mac-security> <mac-learning-priority> <priority>high</priority> </mac-learning-priority> </mac-security> </interface> </interfaces> </top></config>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:b1b8232e-1edf-4f21-a5d9-c51a5c3e05d2"> <ok/></rpc-reply>Delete Mac Learning Priority On Interface
Section titled “Delete Mac Learning Priority On Interface”Request example to delete interface mac learning priority via edit-config.
<config> <top> <interfaces> <interface> <name>Ethernet11</name> <mac-security> <mac-learning-priority operation="delete"> </mac-learning-priority> </mac-security> </interface> </interfaces> </top></config>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:9fbc84a4-f30a-4c8c-8988-58fc29ae92a0"> <ok/></rpc-reply>Get Interface Mac Learning Group Configurations
Section titled “Get Interface Mac Learning Group Configurations”Request example to get interface mac learning group configuration via get-config.
<filter type="subtree"> <top> <interfaces> <interface> <name>Ethernet11</name> <mac-security> <mac-learning-group/> </mac-security> </interface> </interfaces> </top></filter>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:89b6b7be-cf92-454a-ac98-9cff05a2a14b"> <data> <top> <interfaces xmlns="http://asterfusion.com/ns/yang/asternos-interfaces"> <interface> <name>Ethernet11</name> <mac-security xmlns="http://asterfusion.com/ns/yang/asternos-mac-security"> <mac-learning-group>4</mac-learning-group> </mac-security> </interface> </interfaces> </top> </data></rpc-reply>Configure Mac Learning Group On Interface
Section titled “Configure Mac Learning Group On Interface”The default value is 0.
Request example to configure interface mac learning group via edit-config.
<config> <top> <interfaces> <interface> <name>Ethernet11</name> <mac-security> <mac-learning-group>4</mac-learning-group> </mac-security> </interface> </interfaces> </top></config>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:56357799-9c49-4cf8-96ef-aae3d1962c46"> <ok/></rpc-reply>Delete Mac Learning Group On Interface
Section titled “Delete Mac Learning Group On Interface”Request example to delete interface mac learning group via edit-config.
<config> <top> <interfaces> <interface> <name>Ethernet11</name> <mac-security> <mac-learning-group operation="delete"> </mac-learning-group> </mac-security> </interface> </interfaces> </top></config>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:9fbc84a4-f30a-4c8c-8988-58fc29ae92a0"> <ok/></rpc-reply>Get Interface Port-Security Configurations
Section titled “Get Interface Port-Security Configurations”Request example to get interface port-security configuration via get-config.
<filter type="subtree"> <top> <interfaces> <interface> <name>Ethernet11</name> <mac-security> <port-security/> </mac-security> </interface> </interfaces> </top></filter>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:3113721a-11d4-4127-b723-c38de8b389ae"> <data> <top> <interfaces xmlns="http://asterfusion.com/ns/yang/asternos-interfaces"> <interface> <name>Ethernet11</name> <mac-security xmlns="http://asterfusion.com/ns/yang/asternos-mac-security"> <port-security> <enabled>true</enabled> <maximum>3</maximum> <secure-addresses> <secure-address> <mac-address>12:34:56:78:9a:bc</mac-address> <vlan-id>1000</vlan-id> </secure-address> </secure-addresses> </port-security> </mac-security> </interface> </interfaces> </top> </data></rpc-reply>Configure Port-Security On Interface
Section titled “Configure Port-Security On Interface”The default maximum is 1, and default violation-action is restrict. The mac-security can’t configured on the interface which mac-limit is configured. Configure mac-security requires interface which is a vlan member.
Request example to configure interface port-security via edit-config.
<config> <top> <interfaces> <interface> <name>Ethernet11</name> <mac-security> <port-security> <enabled>true</enabled> <sticky-enabled>true</sticky-enabled> <violation-action>protect</violation-action> <maximum>3</maximum> </port-security> </mac-security> </interface> </interfaces> </top></config>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:e21e82f5-44fb-487b-8397-29ec4ab4f784"> <ok/></rpc-reply>Delete Port-Security On Interface
Section titled “Delete Port-Security On Interface”Request example to delete interface port-security via edit-config.
<config> <top> <interfaces> <interface> <name>Ethernet11</name> <mac-security> <port-security operation="delete"> </port-security> </mac-security> </interface> </interfaces> </top></config>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:8b8293cb-bfeb-4ab1-b054-b2cd9786afc0"> <ok/></rpc-reply>Configure Static Secure Mac On Interface
Section titled “Configure Static Secure Mac On Interface”Create static secure mac on interface requires port-security enabled on device.
Request example to configure interface port-security via edit-config.
<config> <top> <interfaces> <interface> <name>Ethernet11</name> <mac-security> <port-security> <enabled>true</enabled> <maximum>3</maximum> <secure-addresses operation="create"> <secure-address> <mac-address>12:34:56:78:9a:bc</mac-address> <vlan-id>1000</vlan-id> </secure-address> </secure-addresses> </port-security> </mac-security> </interface> </interfaces> </top></config>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:fc234ab7-0542-45c5-95ce-01bb9bcf3269"> <ok/></rpc-reply>Delete Static Secure Mac On Interface
Section titled “Delete Static Secure Mac On Interface”Request example to delete interface static secure mac via edit-config.
<config> <top> <interfaces> <interface> <name>Ethernet11</name> <mac-security> <port-security> <secure-addresses operation="delete"> </secure-addresses> </port-security> </mac-security> </interface> </interfaces> </top></config>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:c5b76a0d-3c46-4292-9b31-d70cf453afb4"> <ok/></rpc-reply>Show Mac Limit
Section titled “Show Mac Limit”Interfaces that are not displayed have a default value of 0, which means no limit.
Request example to show interface mac limit via rpc show-mac-limit.
<show-mac-limit/>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:21e9337e-f29f-4f39-9ec0-ad4e0208157f"> <data xmlns="http://asterfusion.com/ns/yang/asternos-mac-security"> Interface Mac-limit ----------- ----------- Ethernet1 0 Ethernet11 20 </data></rpc-reply>Show Mac Learning Priority
Section titled “Show Mac Learning Priority”Request example to show interface mac learning priority via rpc show-mac-learning-priority.
<show-mac-learning-priority/>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:9afc7076-a9ad-4c8d-b773-a843091a4d98"> <data xmlns="http://asterfusion.com/ns/yang/asternos-mac-security"> Interface Priority --------------- ---------- Ethernet1 low Ethernet2 low Ethernet3 low Ethernet4 low Ethernet5 low Ethernet6 low Ethernet7 low Ethernet8 low Ethernet9 low Ethernet10 low Ethernet11 high Ethernet12 low Ethernet13 low Ethernet14 low Ethernet15 low Ethernet16 low Ethernet17 low Ethernet18 low Ethernet19 low Ethernet20 low Ethernet21 low Ethernet22 low Ethernet23 low Ethernet24 low Ethernet25 low Ethernet26 low Ethernet27 low Ethernet28 low Ethernet29 low Ethernet30 low Ethernet31 low Ethernet32 low Ethernet33 low Ethernet34 low Ethernet35 low Ethernet36 low Ethernet37 low Ethernet38 low Ethernet39 low Ethernet40 low Ethernet41 low Ethernet42 low Ethernet43 low Ethernet44 low Ethernet45 low Ethernet46 low Ethernet47 low Ethernet48 low Ethernet49 low Ethernet53 low Ethernet57 low Ethernet61 low Ethernet65 low Ethernet69 low Ethernet73 low Ethernet77 low PortChannel0001 low </data></rpc-reply>Show Mac Learning Group
Section titled “Show Mac Learning Group”Request example to show interface mac learning group via rpc show-mac-learning-group.
<show-mac-learning-group/>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:3cfe03ca-8083-4305-87cc-e764976e7dcd"> <data xmlns="http://asterfusion.com/ns/yang/asternos-mac-security"> Interface Group-Id --------------- ---------- Ethernet1 0 Ethernet2 0 Ethernet3 0 Ethernet4 0 Ethernet5 0 Ethernet6 0 Ethernet7 0 Ethernet8 0 Ethernet9 0 Ethernet10 0 Ethernet11 4 Ethernet12 0 Ethernet13 0 Ethernet14 0 Ethernet15 0 Ethernet16 0 Ethernet17 0 Ethernet18 0 Ethernet19 0 Ethernet20 0 Ethernet21 0 Ethernet22 0 Ethernet23 0 Ethernet24 0 Ethernet25 0 Ethernet26 0 Ethernet27 0 Ethernet28 0 Ethernet29 0 Ethernet30 0 Ethernet31 0 Ethernet32 0 Ethernet33 0 Ethernet34 0 Ethernet35 0 Ethernet36 0 Ethernet37 0 Ethernet38 0 Ethernet39 0 Ethernet40 0 Ethernet41 0 Ethernet42 0 Ethernet43 0 Ethernet44 0 Ethernet45 0 Ethernet46 0 Ethernet47 0 Ethernet48 0 Ethernet49 0 Ethernet53 0 Ethernet57 0 Ethernet61 0 Ethernet65 0 Ethernet69 0 Ethernet73 0 Ethernet77 0 PortChannel0001 0 </data></rpc-reply>Show Port Security Status
Section titled “Show Port Security Status”Request example to show interface mac port security via rpc show-port-security.
<show-port-security/>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:db3c9b93-7cee-4235-a410-3b85328eb4fa"> <data xmlns="http://asterfusion.com/ns/yang/asternos-mac-security"> Interface Port-Security Sticky-Mac Max-Secure-Addr Violation-Action ----------- --------------- ------------ ----------------- ------------------ Ethernet11 enable disable 3 restrict </data></rpc-reply>Show Port Security addresses
Section titled “Show Port Security addresses”Both static and dynamic learned Secure MAC addresses will be retrieved.
Request example to show interface mac port security addresses via rpc show-port-security-address.
<show-port-security-address/>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:b59ae792-b2f8-4ce9-a17a-783b2688bf3f"> <data> <mac-address-info> <vlan-id>Vlan1000</vlan-id> <mac-address>12:34:56:78:9a:bc</mac-address> <type>static</type> <port>Ethernet11</port> <index>1</index> </mac-address-info> <mac-address-info> <vlan-id>Vlan10</vlan-id> <mac-address>60:eb:5a:01:1c:e4</mac-address> <type>dynamic</type> <port>Ethernet1</port> <index>2</index> </mac-address-info> </data></rpc-reply>Clear All Port Security addresses
Section titled “Clear All Port Security addresses”Both static and dynamic learned Secure MAC addresses will be deleted.
Request example to clear interface mac port security addresses via rpc clear-port-security-address.
<clear-port-security-address/>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:a9cdd8de-9722-41f9-911f-297301d36a7e"> <data xmlns="http://asterfusion.com/ns/yang/asternos-mac-security"> success </data></rpc-reply>Clear Single Port Security addresses
Section titled “Clear Single Port Security addresses”Request example to clear interface mac port security addresses via rpc clear-port-security-address.
<clear-port-security-address> <interface>Ethernet11</interface></clear-port-security-address>Response example
<rpc-reply xmlns="urn:ietf:params:xml:ns:netconf:base:1.0" message-id="urn:uuid:5c9a8281-8e6a-44bd-938f-55987af27e75"> <data xmlns="http://asterfusion.com/ns/yang/asternos-mac-security"> success </data></rpc-reply>Properties Descriptions
Section titled “Properties Descriptions”Mac Security
Section titled “Mac Security”Tree Diagram
module: asternos-mac-security
augment /if:interfaces/if:interface: +--rw mac-securityMac Learning Priority
Section titled “Mac Learning Priority”Tree Diagram
module: asternos-mac-security
augment /if:interfaces/if:interface: +--rw mac-securityMac Limit
Section titled “Mac Limit”Tree Diagram
module: asternos-mac-security
augment /if:interfaces/if:interface: +--rw mac-securityPort Security
Section titled “Port Security”Tree Diagram
module: asternos-mac-security
augment /if:interfaces/if:interface: +--rw mac-securitySecure Address
Section titled “Secure Address”Tree Diagram
module: asternos-mac-security
augment /if:interfaces/if:interface: +--rw mac-securityShow Mac Limit
Section titled “Show Mac Limit”Tree Diagram
module: asternos-mac-security
augment /if:interfaces/if:interface: +--rw mac-security
rpcs: +---x show-mac-limit +---w input | +---w (filter) | +--:(port-name) | | +---w port-name? cmn:ethernet-port-name | +--:(portchannel-name) | | +---w portchannel-name? cmn:port-channel-name | +--:(vlan-id) | | +---w vlan-id? cmn:vlan-id | +--:(all) | +---w all? empty +--ro output +--ro data? <anydata>Table of Properties
| Name | Required | Type/Range | Description |
|---|---|---|---|
| show-mac-limit | O | ||
| port-name | O | cmn:ethernet-port-name | Name of the Ethernet interface. |
| portchannel-name | O | cmn:port-channel-name | Name of the portchannel interface. |
| vlan-id | O | cmn:vlan-id | VLAN ID |
| all | O | empty | show all mac limit |
| data | O | A table that shows MAC address learning limit information |
Show Port Security Address
Section titled “Show Port Security Address”Tree Diagram
module: asternos-mac-security
augment /if:interfaces/if:interface: +--rw mac-security
rpcs: +---x show-port-security-address +---w input | +---w interface? union +--ro output +--ro data? <anydata>Table of Properties
| Name | Required | Type/Range | Description |
|---|---|---|---|
| show-port-security-address | O | ||
| interface | O | Ethernet name | Name of the Ethernet or PortChannel (empty for all interfaces). |
| data | O | show secure mac addresses |
Clear Port Security Address
Section titled “Clear Port Security Address”Tree Diagram
module: asternos-mac-security
augment /if:interfaces/if:interface: +--rw mac-security
rpcs: +---x clear-port-security-address +---w input | +---w interface? union | +---w fdb-type? enumeration +--ro output +--ro data? <anydata>Table of Properties
| Name | Required | Type/Range | Description |
|---|---|---|---|
| clear-port-security-address | O | ||
| interface | O | Ethernet name | Name of the Ethernet or PortChannel (empty for all interfaces). |
| fdb-type | O | ”static" "dynamic" "sticky" "all” | The type of fdb to clear (empty for all types). |
| data | O | The string indicates success or failure of this operation |
Show Mac Learning Group
Section titled “Show Mac Learning Group”Tree Diagram
module: asternos-mac-security
augment /if:interfaces/if:interface: +--rw mac-security
rpcs: +---x show-mac-learning-group +---w input | +---w interface? union +--ro output +--ro data? <anydata>Table of Properties
| Name | Required | Type/Range | Description |
|---|---|---|---|
| show-mac-learning-group | O | ||
| interface | O | Ethernet name | Name of the Ethernet or PortChannel (empty for all interfaces) |
| data | O | show port mac learning group id configurations |
Show Mac Learning Priority
Section titled “Show Mac Learning Priority”Tree Diagram
module: asternos-mac-security
augment /if:interfaces/if:interface: +--rw mac-security
rpcs: +---x show-mac-learning-priority +---w input | +---w interface? union +--ro output +--ro data? <anydata>Table of Properties
| Name | Required | Type/Range | Description |
|---|---|---|---|
| show-mac-learning-priority | O | ||
| interface | O | Ethernet name | Name of the Ethernet or PortChannel (empty for all interfaces) |
| data | O | show port mac learning priority configurations |
Show Port Security
Section titled “Show Port Security”Tree Diagram
module: asternos-mac-security
augment /if:interfaces/if:interface: +--rw mac-security
rpcs: +---x show-port-security +---w input | +---w interface? union +--ro output +--ro data? <anydata>Table of Properties
| Name | Required | Type/Range | Description |
|---|---|---|---|
| show-port-security | O | ||
| interface | O | Ethernet name | Name of the Ethernet or PortChannel (empty for all interfaces) |
| data | O | show port security configurations |