111
Enabling port security
Configuration prerequisites
To enable port security, you must first disable 802.1X and MAC authentication globally.
Configuration procedure
To enable port security:
To do…
Use the command…
Remarks
1.
Enter system view.
system-view
—
2.
Enable port security.
port-security enable
Required.
By default, the port security is disabled.
Enabling or disabling port security resets the following security settings to the default:
•
802.1X access control mode is MAC-based, and the port authorization state is
auto
.
•
Port security mode is
noRestrictions
.
When port security is enabled, you cannot manually enable 802.1X or MAC authentication or change
the access control mode or port authorization state. The port security automatically modifies these
settings in different security modes.
You cannot disable port security when online users are present.
For more information about 802.1X configuration, see "
For more information about MAC authentication configuration, see "
Configuring MAC authentication
Setting port security’s limit on the number of MAC
addresses on a port
You can set the maximum number of MAC addresses that port security allows on a port for the following
purposes:
•
Controlling the number of concurrent users on the port. The maximum number of concurrent users
on the port equals this limit or the limit of the authentication mode (802.1X, for example) in use,
whichever is smaller.
•
Controlling the number of secure MAC addresses on the port in autoLearn mode.
To set the maximum number of secure MAC addresses allowed on a port:
To do…
Use the command…
Remarks
1.
Enter system view.
system-view
—
2.
Enter Layer 2 Ethernet
interface view.
interface
interface-type
interface-
number
—
3.
Set the limit of port security on
the number of MAC
addresses.
port-security max-mac-count
count-value
Required
Not limited by default