How do I block a suspect mac-address on a customer edge router or switch? On Huawei exists a command that reminds me of the shun option on Cisco ASA: mac-address blackhole mac-address { vlan vlan-id | vsi vsi-name } Works both in VLAN and VPLS environment.