DGS-3312SR Stackable Gigabit Layer 3 Switch
96
Port Security Configuration
The following three windows will allow the user to implement security functions on a per port basis on the Switch or a
switch in a switch stack. To access the following windows, open the
Port Security Configuration
folder in the
Configuration
folder.
Port Security
A given port’s (or a range of port’s) dynamic MAC address learning can be locked such that the current source MAC
addresses entered into the MAC address forwarding table can not be changed once the port lock is enabled. The port can be
locked by using the Admin State
pull-down menu to
Enabled
, and clicking
Apply
.
This is a security feature that prevents unauthorized computers (with source MAC addresses unknown to the Switch prior
to locking the port (or ports) from connecting to the Switch’s locked ports and gaining access to the network.
Figure 4- 65. Port Security Settings window
The following parameters can be set:
Parameter
Description
Unit
Allows you to specify a Switch in a Switch stack using that Switch’s Unit ID. The
number 15 indicates a Switch in standalone mode.
From/To
A consecutive group of ports may be configured starting with the selected port.
Admin State
This pull-down menu allows you to enable or disable Port Security (locked MAC address
table for the selected ports.)
Max.Addr (0-10)
The number of MAC addresses that will be in the MAC address forwarding table for the
selected Switch and group of ports.
Lock Address
Mode
This pull-down menu allows you to select how the MAC address table locking will be
implemented on the Switch, for the selected group of ports. The options are:
•
Permanent
– The locked addresses will not age out after the aging timer
expires.
•
DeleteOnTimeout
– The locked addresses will age out after the aging timer
expires.
DeleteOnReset
– The locked addresses will not age out until the Switch has been reset.