![Asante IntraCore 36000 Series User Manual Download Page 272](http://html.mh-extra.com/html/asante/intracore-36000-series/intracore-36000-series_user-manual_2980500272.webp)
272
Asanté IntraCore 36000 Series
16.123 port security
This command enables or configures port security. Use the no form without any keywords to disable port
security. Use the no form with the appropriate keyword to restore the default settings for a response to
security violation or for the maximum number of allowed addresses.
Syntax Description
port security [action {shutdown | trap | trap-and-shutdown} |
max-mac-
count
address-count
]
no
port security [action | max-mac-count]
action
Response to take when port security is violated.
shutdown
- Disable port only.
trap
- Issue SNMP trap message only.
trap-and-shutdown
- Issue SNMP trap message and disable port.
max-mac-count
The maximum number of MAC addresses that can be counted on a port.
(Range: 0 - 20)
address-count
The maximum number of MAC addresses that can be learned on a port.
(Range: 0 - 20)
Default
Status: Disabled
Action: None
Maximum Addresses: 0
Command Mode
Interface Configuration (Ethernet)
Usage Guidelines
If you enable port security, the switch stops dynamically learning new addresses on the specified port. Only
incoming traffic with source addresses already stored in the dynamic or static address table are accepted.
To use port security, first allow the switch to dynamically learn the <source MAC address, VLAN> pair for
frames received on a port for an initial training period, and then enable port security to stop address
learning. Be sure you enable the learning function long enough to ensure that all valid VLAN members have
been registered on the selected port.
To add new VLAN members at a later time, you can manually add secure addresses with the mac-address-
table static command, or turn off port security to re-enable the learning function long enough for new VLAN
members to be registered. Learning may then be disabled again, if desired, for security.
A secure port has the following restrictions:
•
Cannot use port monitoring.