14-37
Configuring and Monitoring Port Security
Reading Intrusion Alerts and Resetting Alert Flags
Figure 14-15.Example of an Unacknowledged Intrusion Alert in a Port Status Display
If you wanted to see the details of the intrusion, you would then enter the
show
port-security intrusion-log
command. For example:
Figure 14-16.Example of the Intrusion Log with Multiple Entries for the Same Port
The above example shows three intrusions for port A1. Since the switch can
show only one uncleared intrusion per port, the older two intrusions in this
example have already been cleared by earlier use of the
clear intrusion-log
or
the
port-security <
port-list
> clear-intrusion-flag
command. (The intrusion log
holds up to 20 intrusion records, and deletes intrusion records only when the
log becomes full and new intrusions are subsequently added.) The “
prior to
”
text in the record for the third intrusion means that a switch reset occurred
at the indicated time and that the intrusion occurred prior to the reset.
To clear the intrusion from port A1 and enable the switch to enter any
subsequent intrusion for port A1 in the Intrusion Log, execute the port-security
clear-intrusion-flag
command. If you then re-display the port status screen, you
HP Switch(config)# show int brief
Status and Counters - Port Status
| Intrusion MDI Flow Bcast
Port Type | Alert Enabled Status Mode Mode Ctrl Limit
------ --------- + --------- ------- ------ ---------- ---- ---- -----
B1 100/1000T | Yes Yes Up 1000FDx MDI off 0
B2 100/1000T | No Yes Up 1000FDx Auto off 0
B3 100/1000T | No Yes Up 1000FDx Auto off 0
B4 100/1000T | No Yes Up 1000FDx Auto off 0
Intrusion Alert on port B1.
Dates and Times of
Intrusions
MAC Address of latest
Intruder on Port 1
Earlier intrusions on
port 1 that have already
been cleared (that is,
the Alert Flag has been
reset at least twice
before the most recent
intrusion occurred.
HP Switch(config)# show port-security intru-
sion-log
Status and Counters - Intrusion Log
Port MAC Address Date / Time
------ ------------- ------------------------
--
1 080009-e93d4f 09/07/11 21:09:34
1 080009-21ae84 09/07/11 17:06:27
1 080009-e93d4f 09/07/11 17:18:43
Summary of Contents for E3800 Series
Page 2: ......
Page 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Page 30: ...xxviii ...
Page 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Page 186: ...4 72 Web and MAC Authentication Client Status ...
Page 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Page 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Page 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 730: ...20 Index ...
Page 731: ......