CHAPTER 6: ACCESS CONSIDERATIONS
CONFIGURING PORT SECURITY THROUGH THE COMMAND LINE INTERFACE
MULTILINK ML810 MANAGED EDGE SWITCH – INSTRUCTION MANUAL
6–3
6.2
Configuring Port Security through the Command
Line Interface
6.2.1
Commands
To configure port security, login as a level 2 user or as a manager. Once logged in, get to
the port-security configuration level to setup and configure port security with the following
command syntax:
configure port-security
port-security
For example, using the
configure port-security
command:
ML810#
configure port-security
ML810(port-security)##
Alternately, the
port-security
command can also be used to enter the port-security
configuration mode:
ML810#
port-security
ML810#(port-security)##
From the port security configuration mode, the switch can be configured to:
1.
Auto-learn the MAC addresses.
2.
Specify individual MAC addresses to allow access to the network.
3.
Validate or change the settings.
The command syntax for the above actions are:
allow
mac=<address|list|range>
port=<num|list|range>
learn
port=<number-list> <enable|disable>
show port-security
action
port=<num|list|range>
<none|disable|drop>
signal
port=<num|list|range>
<none|log|trap|logandtrap>
ps
<enable|disable>
remove
mac=<all|address|list|range>
port=<num|list|range>
signal
port=<num|list|range>
<none|log|trap|logandtrap>
Where the following hold:
•
allow mac
- configures the switch to setup allowed MAC addresses on specific
ports
•
learn port
- configures the switch to learn the MAC addresses associated with
specific port or a group of ports
•
show port-security
- shows the information on port security programmed or
learnt
•
action port
- specifies the designated action to take in case of a non
authorized access
•
ps
- port security - allows port security to be enable or disabled