339
Examples
# Apply the NAS-ID profile
aaa
to GigabitEthernet 1/0/1 for port security.
<Sysname> system-view
[Sysname] interface gigabitethernet 1/0/1
[Sysname-GigabitEthernet1/0/1] port-security nas-id-profile aaa
# Globally apply the NAS-ID profile
aaa
to port security.
<Sysname> system-view
[Sysname] port-security nas-id-profile aaa
Related commands
aaa nas-id profile
port-security ntk-mode
Use
port-security ntk-mode
to configure the NTK feature.
Use
undo port-security ntk-mode
to restore the default.
Syntax
port-security ntk-mode
{
ntk-withbroadcasts
|
ntk-withmulticasts
|
ntkonly
}
undo port-security ntk-mode
Default
The NTK feature is not configured on a port and all frames are allowed to be sent.
Views
Layer 2 Ethernet interface view
Predefined user roles
network-admin
Parameters
ntk-withbroadcasts
: Forwards only broadcast frames and unicast frames with authenticated
destination MAC addresses.
ntk-withmulticasts
: Forwards only broadcast frames, multicast frames, and unicast frames with
authenticated destination MAC addresses.
ntkonly
: Forwards only unicast frames with authenticated destination MAC addresses.
Usage guidelines
This command is supported only on the following ports:
•
Layer 2 Ethernet ports on the following modules:
HMIM-8GSW.
HMIM-24GSW.
HMIM-24GSWP.
SIC-4GSW.
SIC-4GSWP
•
Fixed Layer 2 Ethernet ports on the following routers:
MSR954 (JH296A/JH297A/JH298A/JH299A/JH373A).
MSR958 (JH300A/JH301A).
MSR2004-24/2004-48.
Summary of Contents for FlexNetwork MSR Series
Page 1005: ...987 ...