© Copyright Lenovo 2017
Chapter 16: VMready
285
Advanced Validation
This
mode
provides
VM
‐
based
validation
by
mapping
a
switch
port
to
a
VM
MAC
address.
It
is
suitable
for
environments
in
which
spoofing,
MAC
reassignment,
or
MAC
duplication
is
possible.
When
the
switch
receives
frames
from
a
VM,
it
first
validates
the
VM
interface
based
on
the
VM
MAC
address,
VM
Universally
Unique
Identifier
(UUID),
Switch
port,
and
Switch
ID
available
in
the
hello
message
information.
Only
if
all
the
four
parameters
are
matched,
the
VM
MAC
address
is
considered
valid.
In
advanced
validation
mode,
if
the
VM
MAC
address
validation
fails,
an
ACL
can
be
created
to
drop
the
traffic
received
from
the
VM
MAC
address
on
the
switch
port.
Use
the
following
command
to
specify
the
number
of
ACLs
to
be
used
for
dropping
traffic:
Use
the
following
command
to
set
the
action
to
be
performed
if
the
switch
is
unable
to
validate
the
VM
MAC
address:
Following
are
the
other
VMcheck
commands:
CN 4093(config)#
virt vmcheck acls max
<1
‐
640>
CN 4093(config)#
virt vmcheck
action advanced
{log|link|acl}
Table 26.
VMcheck
Commands
Command
Description
CN 4093(config)#
virt vmware hello {ena|
hport
<port
number>
|haddr|htimer}
Hello messages setting:
enable/add
port/advertise this IP
address in the hello
messages instead of the
default management IP
address/set the timer to
send the hello messages
CN 4093(config)#
no virt vmware hello
{enable|hport
<port
number>
}
Disable hello
messages/remove port
CN 4093(config)#
[no] virt vmcheck trust
<port
number>
Mark a port as trusted;
Use the no form of the
command to mark port as
untrusted
CN 4093#
no virt vmcheck acl [mac-address
[
<port
number>
]|port]
Delete ACL(s): all
ACLs/an ACL by MAC
address ((optional) and
port number) /all ACLs
installed on a port
Summary of Contents for Flex System Fabric CN4093
Page 27: ... Copyright Lenovo 2017 27 Part 1 Getting Started ...
Page 28: ...28 CN4093 Application Guide for N OS 8 4 ...
Page 58: ...58 CN4093 Application Guide for N OS 8 4 ...
Page 72: ...72 CN4093 Application Guide for N OS 8 4 ...
Page 85: ... Copyright Lenovo 2017 85 Part 2 Securing the Switch ...
Page 86: ...86 CN4093 Application Guide for N OS 8 4 ...
Page 98: ...98 CN4093 Application Guide for N OS 8 4 ...
Page 112: ...112 CN4093 Application Guide for N OS 8 4 ...
Page 136: ...136 CN4093 Application Guide for N OS 8 4 ...
Page 156: ...156 CN4093 Application Guide for N OS 8 4 ...
Page 192: ...192 CN4093 Application Guide for N OS 8 4 ...
Page 228: ...228 CN4093 Application Guide for N OS 8 4 ...
Page 229: ... Copyright Lenovo 2017 229 Part 4 Advanced Switching Features ...
Page 230: ...230 CN4093 Application Guide for N OS 8 4 ...
Page 298: ...298 CN4093 Application Guide for N OS 8 4 ...
Page 382: ...382 CN4093 Application Guide for N OS 8 4 ...
Page 392: ...392 CN4093 Application Guide for N OS 8 4 ...
Page 416: ...416 CN4093 Application Guide for N OS 8 4 ...
Page 452: ...452 CN4093 Application Guide for N OS 8 4 ...
Page 466: ...466 CN4093 Application Guide for N OS 8 4 ...
Page 496: ...496 CN4093 Application Guide for N OS 8 4 ...
Page 508: ...508 CN4093 Application Guide for N OS 8 4 ...
Page 510: ...510 CN4093 Application Guide for N OS 8 4 ...
Page 514: ...514 CN4093 Application Guide for N OS 8 4 ...
Page 538: ...538 CN4093 Application Guide for N OS 8 4 ...
Page 539: ... Copyright Lenovo 2017 539 Part 7 Network Management ...
Page 540: ...540 CN4093 Application Guide for N OS 8 4 ...
Page 554: ...554 CN4093 Application Guide for N OS 8 4 ...
Page 576: ...576 CN4093 Application Guide for N OS 8 4 ...
Page 596: ...596 CN4093 Application Guide for N OS 8 4 ...
Page 604: ...604 CN4093 Application Guide for N OS 8 4 ...
Page 609: ... Copyright Lenovo 2017 609 Part 9 Appendices ...
Page 610: ...610 CN4093 Application Guide for N OS 8 4 ...
Page 626: ...626 CN4093 Application Guide for N OS 8 4 ...
Page 633: ......
Page 634: ...Part Number 00MY375 Printed in USA IP P N 00MY375 ...