145
Control the number of secure MAC addresses that a port can learn for port security.
Control the maximum number of users who are allowed to access the network through the port.
Follow these steps to set the maximum number of secure MAC addresses allowed on a port:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter Layer 2 Ethernet interface
view
interface
interface-type
interface-
number
—
Set the maximum number of
secure MAC addresses allowed
on a port
port-security max-mac-count
count-value
Required
Not limited by default
NOTE:
This configuration is independent of the MAC learning limit described in MAC address table
configuration in the
Layer 2—LAN Switching Configuration Guide
.
Setting the port security mode
Configuration prerequisites
Before you set a port security mode for a port, complete the following tasks:
Disable 802.1X and MAC authentication.
Set the port to perform MAC-based access control, and set the port authorization mode to
auto
.
Check the port does not belong to any aggregation group.
The requirements above must be all met. Otherwise, an error message appears when you set a security
mode on the port. On the other hand, after setting a port security mode on a port, you cannot change
any of the configurations above.
Before you configure the port to operate in autoLearn mode, set the maximum number of secure
MAC addresses allowed on a port.
NOTE:
With port security disabled, you can configure a port security mode, but your configuration does not take effect.
You cannot change the port security mode of a port with users online.
Configuration procedure
Follow these steps to enable any other port security mode:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Set an OUI value for user
authentication
port-security
oui
oui-value
index
index-value
Optional
Not configured by default.
The command is required for the
userlogin-withoui
mode.