Setting mac-nospoof for a NGZ (net) interface managed by allowed-address
I have the following network interface:
root@server-1:~# dladm show-phys net7
LINK MEDIA STATE SPEED DUPLEX DEVICE
net7 Ethernet unknown 1000 full e1000g11
root@server-1:~# dladm show-phys -m net7
LINK SLOT ADDRESS INUSE CLIENT
net7 primary 8:0:27:ad:65:e no --
root@server-1:~# dladm show-linkprop -p allowed-ips,protection net7
LINK PROPERTY PERM VALUE DEFAULT POSSIBLE
net7 allowed-ips rw -- -- --
net7 protection rw -- -- mac-nospoof,
restricted,
ip-nospoof,
dhcp-nospoof
Then I use it for a NGZ:
root@server-1:~# dladm show-phys net7
LINK MEDIA STATE SPEED DUPLEX DEVICE
net7 Ethernet unknown 1000 full e1000g11
root@server-1:~# dladm show-phys -m net7
LINK SLOT ADDRESS INUSE CLIENT
net7 primary 8:0:27:ad:65:e no --
root@server-1:~# dladm show-linkprop -p allowed-ips,protection net7
LINK PROPERTY PERM VALUE DEFAULT POSSIBLE
net7 allowed-ips rw -- -- --
net7 protection rw -- -- mac-nospoof,
restricted,
ip-nospoof,
dhcp-nospoof
root@server-1:~# zoneadm -z server-1g list -v
ID NAME STATUS PATH BRAND IP
- server-1g installed /zone/server-1g solaris excl
root@server-1:~# zonecfg -z server-1g info net
ID NAME STATUS PATH BRAND IP
- server-1g installed /zone/server-1g solaris excl
root@server-1:~# zonecfg -z server-1g info net
0