< Home

Configuring Across-Layer-3 MAC Identification Using the Web UI

This section describes how to configure across-Layer-3 MAC identification using the Web UI.

Prerequisites

Before configuring the across-Layer-3 MAC identification function, ensure that the Layer-3 network device connected to the FW supports SNMPv2c or SNMP v3, and the SNMP agent has been enabled and community name has been configured on the network device.

Context

Intranet users use the FW to access the Internet, and the FW uses MAC addresses as matching conditions to control intranet traffic. If the FW uses a Layer-3 network device to connect to an intranet PC, the FW cannot obtain the MAC address of the intranet PC directly.

Therefore, across-Layer-3 MAC address identification must be enabled on the FW to synchronize ARP entries from the Layer-3 network device using SNMP to obtain MAC addresses of intranet PCs.
If multiple Layer-3 network devices are deployed between the FW and an intranet PC, you are advised to specify a network device closest to the intranet PC as the SNMP server. The FW can serve multiple Layer-3 devices (SNMP servers) to synchronize ARP entries.

Procedure

  1. Choose System > Configuration > Across-Layer-3 MAC Identification.

  2. Enable the across-layer-3 MAC identification function in Across-Layer-3 MAC Identification.
  3. Optional: Enter the parameters.

    Parameter

    Description

    SNMP Server Access Interval

    Interval between two SNMP requests.

    SNMP Server Access Timeout

    Length of time the SNMP server waits for a response to a request sent to the target network device. You can specify this parameter based on the update interval of a PC IP address and the network delay.

  4. Click Apply.
  5. Add an SNMP server.
    1. Click Add.
    2. Configure an ID for the SNMP server.

      Parameter

      Description

      SNMP Version

      SNMP version of the SNMP server:

      • v2c

      • v3

      SNMP Server

      IP address of the target Layer-3 network device.

      Select an IP address from the existing IP addresses of Layer-3 network devices.

      The device supports 64 Layer-3 network devices as SNMP servers to synchronize ARP entries.

      SNMPv3 Security User Name

      Uer name must have been configured on a specific Layer-3 network device, and the user name and IP address must identify the same Layer-3 network device.

      Authentication Mode

      Authentication password must be the same as that on the SNMP server.

      Authentication Password

      Encryption Mode

      Encryption Password

    3. Click OK.
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >