Example: Configuring MFF in a ring network
Network configuration
As shown in Figure 175, all the devices are in VLAN 100, and the switches form a ring. Hosts A, B, and C are assigned IP addresses manually.
Configure MFF to isolate the hosts at Layer 2 and allow them to communicate with each other through the gateway at Layer 3.
Figure 175: Network diagram
Procedure
Configure the IP addresses of the hosts and the gateway, as in shown in Figure 175.
Configure Switch A:
# Enable STP globally to make sure STP is enabled on interfaces.
[SwitchA] stp global enable
# Configure MFF on VLAN 100.
[SwitchA] vlan 100 [SwitchA-vlan100] mac-forced-forwarding default-gateway 10.1.1.100
# Specify the IP address of the server.
[SwitchA-vlan100] mac-forced-forwarding server 10.1.1.200
# Enable ARP snooping on VLAN 100.
[SwitchA-vlan100] arp snooping enable [SwitchA-vlan100] quit
# Configure HundredGigE 1/0/2 and HundredGigE 1/0/3 as network ports.
[SwitchA] interface hundredgige 1/0/2 [SwitchA-HundredGigE1/0/2] mac-forced-forwarding network-port [SwitchA-HundredGigE1/0/2] quit [SwitchA] interface hundredgige 1/0/3 [SwitchA-HundredGigE1/0/3] mac-forced-forwarding network-port
Configure Switch B:
# Enable STP globally to make sure STP is enabled on interfaces.
[SwitchB] stp global enable
# Configure MFF on VLAN 100.
[SwitchB] vlan 100 [SwitchB-vlan100] mac-forced-forwarding default-gateway 10.1.1.100
# Specify the IP address of the server.
[SwitchB-vlan100] mac-forced-forwarding server 10.1.1.200
# Enable ARP snooping on VLAN 100.
[SwitchB-vlan100] arp snooping enable [SwitchB-vlan100] quit
# Configure HundredGigE 1/0/1 and HundredGigE 1/0/3 as network ports.
[SwitchB] interface hundredgige 1/0/1 [SwitchB-HundredGigE1/0/1] mac-forced-forwarding network-port [SwitchB-HundredGigE1/0/1] quit [SwitchB] interface hundredgige 1/0/3 [SwitchB-HundredGigE1/0/3] mac-forced-forwarding network-port
Enable STP on Switch C globally to make sure STP is enabled on interfaces.
<SwitchC> system-view [SwitchC] stp global enable