
4 Web-based Switch Configuration
D-Link DGS-2000 Series Ethernet Switch User Manual
8
8
5
5
A given ports’ (or a range of ports') dynamic MAC address learning can be stopped such that the current
source MAC addresses entered into the MAC address forwarding table cannot be changed once the port is
enabled.
Figure 4.116 - Security > Port Security
The Port Security page contains the following fields:
From Port/To Port:
A consecutive group of ports may be configured starting with the selected port.
Admin State:
This pull-down menu allows users to enable or disable Port Security (locked MAC address
table for the selected ports).
Max. Learning Address (0-64):
The number of MAC addresses that will be in the MAC address-forwarding
table for the selected switch and group of ports.
Lock Address Mode:
This pull-down menu allows user to select how the MAC address table locking will be
implemented on the Switch, for the selected group of ports. The options are:
Delete On Reset –
The locked addresses will not age out until the Switch has been reset.
Delete On Timeout –
The locked addresses will age out after the aging timer expires.
Permanent –
The locked addresses will not age out after the aging timer expires.
Click
Apply
to make configurations make effects.
Security > Port Security FDB Entry
The page displays the MAC entries that trigger port security reaction.
Figure 4.117 - Configuration > Port Security FDB Entry
By click
Delete
, the MAC entry will be released for Port Security FDB.
Security > 802.1X > 802.1X Settings
Network switches provide easy and open access to resources by simply attaching a client PC. Unfortunately
this automatic configuration also allows unauthorized personnel to easily intrude and possibly gain access to
sensitive data.
IEEE-802.1X provides a security standard for network access control, especially in Wi-Fi wireless networks.
802.1X holds a network port disconnected until authentication is completed. The switch uses Extensible
Authentication Protocol over LANs (EAPOL) to exchange authentication protocol client identity (such as a