14-1
14
Configuring and Monitoring Port Security
Overview
This feature enables you to configure each
switch port with a unique list of the MAC addresses of devices that are
authorized to access the network through that port. This enables individual
ports to detect, prevent, and log attempts by unauthorized devices to commu-
nicate through the switch.
N o t e
This feature does not prevent intruders from receiving broadcast and multi-
cast traffic. Also, Port Security and MAC Lockdown are mutually exclusive on
a switch. If one is enabled, then the other cannot be used.
MAC Lockdown (Page 14-23).
This feature, also known as “Static
Addressing”, is used to prevent station movement and MAC address “hijack-
ing” by allowing a given MAC address to use only an assigned port on the
switch. MAC Lockdown also restricts the client device to a specific VLAN.
(See also the
Note
, above.)
MAC Lockout (Page 14-31).
This feature enables you to block a specific
MAC address so that the switch drops all traffic to or from the specified
address.
Feature
Default
Menu
CLI
WebAgent
Displaying Current Port Security
n/a
—
Configuring Port Security
disabled
—
Retention of Static Addresses
n/a
—
n/a
MAC Lockdown
disabled
—
MAC Lockout
disabled
—
Intrusion Alerts and Alert Flags
n/a
Summary of Contents for E3800 Series
Page 2: ......
Page 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Page 30: ...xxviii ...
Page 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Page 186: ...4 72 Web and MAC Authentication Client Status ...
Page 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Page 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Page 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 730: ...20 Index ...
Page 731: ......