You can configure a limit rule for learning dynamic MAC addresses.
A limit rule for learning dynamic MAC addresses is applicable to insecure networks with fixed access users, such as cell access network or intranet that lacks security management.
When the number of access users reaches the upper limit, the MAC addresses of new users cannot be learned, and the packets of the new users are discarded.
system-view
interface interface-type interface-number
portswitch
mac-limit { maximum max | action { discard | forward } } *