144
Task
Remarks
Ignoring authorization information from the server
Optional
Enabling port security
Configuration prerequisites
Disable 802.1X and MAC authentication globally.
Configuration procedure
Follow these steps to enable port security:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enable port security
port-security enable
Required
Disabled by default.
1.
Enabling port security resets the following configurations on a port to the bracketed defaults. Then,
values of these configurations cannot be changed manually; the system will adjust them based on
the port security mode automatically:
802.1X (
disabled
), port access control method (
macbased
), and port authorization mode (
auto
)
MAC authentication (
disabled
)
2.
Disabling port security resets the following configurations on a port to the bracketed defaults:
Port security mode (
noRestrictions
)
802.1X (
disabled
), port access control method (
macbased
), and port authorization mode (
auto
)
MAC authentication (
disabled
)
3.
Port security cannot be disabled when a user is present on a port.
NOTE:
For more information about 802.1X configuration, see the chapter “802.1X configuration.”
For more information about MAC authentication configuration, see the chapter “MAC authentication
configuration.”
Setting the maximum number of secure MAC
addresses
The maximum number of users a port supports in a port security mode is determined by the maximum
number of secure MAC addresses or the maximum number of authenticated users that the security mode
supports, whichever is smaller.
By setting the maximum number of MAC addresses allowed on a port, you can implement the following
control: