140
Port security configuration
Port security overview
Port security is a MAC address-based security mechanism for network access control. It is an extension to
the existing 802.1X authentication and MAC authentication. It prevents access of unauthorized devices to
a network by checking the source MAC address of inbound traffic and access to unauthorized devices by
checking the destination MAC address of outbound traffic.
Port security enables you to control MAC address learning and authentication on ports. This enables the
port to learn legal source MAC addresses.
With port security enabled, frames whose source MAC addresses cannot be learned by the device in a
security mode are considered illegal; the events that users do not pass 802.1X authentication or MAC
authentication are considered illegal.
Upon detection of illegal frames or events, the device takes the pre-defined action automatically. When
enhancing the system security, this also greatly reduces your maintenance burden.
NOTE:
The security modes of the port security feature provide extended and combined use of 802.1X
authentication and MAC authentication. They apply to scenarios that require both 802.1X
authentication and MAC authentication. For scenarios that require only 802.1X authentication or MAC
authentication, HP recommends you configure 802.1X authentication or MAC authentication rather
than port security. For information about 802.1X and MAC authentication, see the chapters “802.1X
configuration” and “MAC authentication configuration
.
”
Port security features
NTK
The need to know (NTK) feature checks the destination MAC addresses in outbound frames and allows
frames to be sent to only devices and hosts that have passed authentication or are using MAC addresses
on the MAC address list. This prevents illegal devices from intercepting network traffic.
Intrusion protection
The intrusion protection feature checks the source MAC address in inbound frames for illegal frames and
takes a pre-defined action on each detected illegal frame. The action can be disabling the port
temporarily, disabling the port permanently, or blocking frames from the illegal MAC address for three
minutes (not user configurable).
Port security traps
You can configure the port security module to send traps for port security events such as login, logoff, and
MAC authentication. These traps help you monitor user behaviors.
Port security modes
Port security supports the following categories of security modes: