13
Syntax
port-security intrusion-mode
{
blockmac
|
disableport
|
disableport-temporarily
}
undo port-security intrusion-mode
Default
Intrusion protection is disabled.
Views
Layer 2 Ethernet interface view
Predefined user roles
network-admin
Parameters
blockmac
: Adds the source MAC addresses of illegal frames to the blocked MAC address list and
discards frames with blocked source MAC addresses for a period set by the block timer. A blocked
MAC address will be unblocked when the block timer expires. The timer is fixed at 3 minutes. To
display the blocked MAC address list, use the
display port-security mac-address block
command.
disableport
: Disables the port permanently when an illegal frame is received on the port.
disableport-temporarily
: Disables the port for a period of time whenever it receives an
illegal frame. You can use the
port-security timer disableport
command to set the
period.
Usage guidelines
To bring up the port disabled by the intrusion protection feature, use the
undo shutdown
command.
Examples
# Configure GigabitEthernet 1/0/1 to block the source MAC addresses of illegal frames after
intrusion protection detects the illegal frames.
<Sysname> system-view
[Sysname] interface gigabitethernet 1/0/1
[Sysname-GigabitEthernet1/0/1] port-security intrusion-mode blockmac
Related commands
display port-security
display port-security mac-address block
port-security timer disableport
port-security mac-address aging-type inactivity
Use
port-security mac-address aging-type inactivity
to enable inactivity aging for
secure MAC addresses.
Use
undo port-security mac-address aging-type inactivity
to disable inactivity
aging for secure MAC addresses.
Syntax
port-security mac-address aging-type inactivity
undo port-security mac-address aging-type inactivity
Summary of Contents for SOHO IE4300
Page 285: ...i Contents Tcl commands 1 cli 1 tclquit 1 tclsh 2...
Page 288: ...i Contents Python commands 1 exit 1 python 1 python filename 2...
Page 291: ...i Contents Automatic configuration commands 1 autodeploy udisk enable 1...
Page 323: ...25 Sysname Ten GigabitEthernet1 0 51 undo shutdown Related commands irf port...
Page 465: ...ii stp vlan enable 55 vlan mapping modulo 55...
Page 602: ...12 Related commands display mvrp statistics...
Page 609: ...i Contents VLAN mapping commands 1 display vlan mapping 1 vlan mapping 2...
Page 678: ...9 Related commands reset pppoe relay statistics...
Page 846: ...i Contents Basic IP forwarding commands 1 display fib 1 ip forwarding table save 2...
Page 1770: ...i Contents Time range commands 1 display time range 1 time range 1...
Page 2026: ...34 Related commands display mac authentication...
Page 2028: ...ii...
Page 2143: ...i Contents User profile commands 1 display user profile 1 user profile 2...
Page 2308: ...61 ipsec transform set...
Page 2531: ...i Contents SAVI commands 1 ipv6 savi down delay 1 ipv6 savi log enable 1 ipv6 savi strict 2...
Page 2534: ...3 Sysname ipv6 savi strict Related commands ipv6 verify source...
Page 2791: ...14 Sysname track 1 Related commands delay display track...
Page 2939: ...9 sntp authentication keyid sntp reliable authentication keyid...
Page 2967: ...27 Related commands apply poe profile poe enable poe max power interface view poe priority...