1-6
To do…
Use the command…
Remarks
Enable port security
port-security enable
Required
Disabled by default
Note that:
1) Enabling port security resets the following configurations on a port to the bracketed defaults. Then,
values of these configurations cannot be changed manually; the system will adjust them based on
the port security mode automatically:
z
802.1X (disabled), port access control method (macbased), and port access control mode (auto)
z
MAC authentication (disabled)
2) Disabling port security resets the following configurations on a port to the bracketed defaults:
z
Port security mode (noRestrictions)
z
802.1X (disabled), port access control method (macbased), and port access control mode (auto)
z
MAC authentication (disabled)
3) Port security cannot be disabled if there is any user present on a port.
z
For detailed 802.1X configuration, refer to
802.1X Configuration
in the
Security Volume
.
z
For detailed MAC-based authentication configuration, refer to
MAC Authentication Configuration
in
the
Security Volume
.
Setting the Maximum Number of Secure MAC Addresses
With port security enabled, more than one authenticated user is allowed on a port. The number of
authenticated users allowed, however, cannot exceed the specified upper limit.
By setting the maximum number of secure MAC addresses allowed on a port, you can:
z
Control the maximum number of users who are allowed to access the network through the port.
z
Control the number of secure MAC addresses that can be added with port security.
Follow these steps to set the maximum number of secure MAC addresses allowed on a port:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter Ethernet port view
interface
interface-type
interface-number
—
Set the maximum number of
secure MAC addresses allowed on
a port
port-security max-mac-count
count-value
Required
Not limited by default
This configuration is different from that of the maximum number of MAC addresses that can be leaned
by the port in MAC address management.