363
Table 125 Configuration items
Item
Description
Port
Select a port where you want to configure port security.
By default, port security is disabled on all ports, and access to the ports is not
restricted.
Max Number of MAC
Set the maximum number of secure MAC addresses on the port.
The number of authenticated users on the port cannot exceed the specified
upper limit.
You can set the maximum number of MAC addresses that port security allows
on a port for the following purposes:
•
Control the maximum number of concurrent users on the port.
•
Control the number of secure MAC addresses that can be added with port
security.
NOTE:
The port security's limit on the maximum number of MAC addresses on a port is
independent of the MAC learning limit in MAC address table management.
Enable Intrusion
Protection
Specify whether to enable intrusion protection, and select an action to be taken
on illegal frames.
Available actions:
•
Disable Port Temporarily
—Disables the port for a period of time. The
period can be configured in the global settings. For more information, see
"
Configuring global settings for port security
•
Disable Port Permanently
—Disables the port permanently upon
detecting an illegal frame received on the port. The port does not come up
unless you bring it up manually.
•
Block MAC
—Adds the source MAC addresses of illegal frames to the
blocked MAC addresses list and discards the frames. All subsequent
frames sourced from a blocked MAC address will be dropped. A blocked
MAC address is restored to normal state after being blocked for 3 minutes.
The interval is not user configurable.
Enable Outbound
Restriction
Specify whether to enable outbound traffic control, and select a control method.
Available control methods:
•
Only MAC-Known Unicasts
—Allows only unicast frames with their
destination MAC addresses being authenticated to pass through.
•
Only Broadcasts and MAC-Known Unicasts
—Allows only broadcast
and unicast packets with their destination MAC addresses being
authenticated to pass through.
•
Only Broadcasts, Multicasts, and MAC-Known Unicasts
—Allows only
broadcast, multicast, and known unicast packets with their destination
MAC addresses being authenticated to pass through.
Configuring secure MAC addresses
1.
From the navigation tree, select
Authentication
>
Port Security
.
The
Port Security
page appears.
2.
In the
Security Ports And Secure MAC Address List
area, click
Secure MAC Address List
.
The secure MAC address configuration area displays the secure MAC addresses that have
been learned or configured.
Summary of Contents for FlexNetwork NJ5000
Page 12: ...x Index 440 ...
Page 39: ...27 Figure 16 Configuration complete ...
Page 67: ...55 Figure 47 Displaying the speed settings of ports ...
Page 78: ...66 Figure 59 Loopback test result ...
Page 158: ...146 Figure 156 Creating a static MAC address entry ...
Page 183: ...171 Figure 171 Configuring MSTP globally on Switch D ...
Page 243: ...231 Figure 237 IPv6 active route table ...