196
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable port security.
port-security enable
By default, this feature is
disabled.
You can use the
undo port-security enable
command to disable port security. Because the
command logs off the online users, make sure no online users are present.
Enabling or disabling port security resets the following security settings to the default:
•
802.1X access control mode is MAC-based.
•
Port authorization state is auto.
For more information about 802.1X authentication and MAC authentication configuration, see
"
Configuring MAC authentication
Setting port security's limit on the number of
secure MAC addresses on a port
You can set the maximum number of secure MAC addresses that port security allows on a port for
the following purposes:
•
Controlling the number of concurrent users on the port.
For a port operating in a security mode (except for autoLearn and secure), the upper limit
equals the smaller of the following values:
{
The limit of the secure MAC addresses that port security allows.
{
The limit of concurrent users allowed by the authentication mode in use.
•
Controlling the number of secure MAC addresses on the port in autoLearn mode.
The port security's limit on the number of secure MAC addresses on a port is independent of the
MAC learning limit described in MAC address table configuration. For more information about MAC
address table configuration, see
Layer 2—LAN Switching Configuration Guide
.
To set the maximum number of secure MAC addresses allowed on a port:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter Layer 2 Ethernet
interface view.
interface
interface-type
interface-number
N/A
3.
Set the maximum number of
secure MAC addresses
allowed on a port.
port-security max-mac-count
count-value
The default setting is
4294967295.
Setting the port security mode
Before you set a port security mode for a port, complete the following tasks:
•
Disable 802.1X and MAC authentication.
•
Verify that the port does not belong to any aggregation group or service loopback group.
•
Set port security's limit on the number of secure MAC addresses if you will change the mode to
autoLearn. You cannot change the setting when the port is operating in autoLearn mode.
When you set the port security mode, follow these guidelines:
Summary of Contents for 10500 series
Page 326: ...312 No duration limit for this SA ...