
14-31
Configuring and Monitoring Port Security
MAC Lockdown
Figure 14-16.Connectivity Problems Using MAC Lockdown with Multiple Paths
The resultant connectivity issues would prevent you from locking down
Server A to Switch 1. And when you remove the MAC Lockdown from Switch
1 (to prevent broadcast storms or other connectivity issues), you then open
the network to security problems. The use of MAC Lockdown as shown in the
above figure would defeat the purpose of using MSTP or having an alternate
path.
Technologies such as MSTP or “meshing” are primarily intended for an inter-
nal campus network environment in which all users are trusted. MSTP and
“meshing” do not work well with MAC Lockdown.
If you deploy MAC Lockdown as shown in the Model Topology in figure 14-15
(page 14-29), you should have no problems with either security or connectiv-
ity.
M i x e d U s e r s
Internal
Network
External
Network
Switch 1
Server A
Server A
is locked down
to Switch 1, Uplink 2
PROBLEM:
If this link fails,
traffic to Server A will not use
the backup path via Switch 3
Switch 2
Switch 3
Switch 4
Summary of Contents for HP ProCurve Series 6600
Page 2: ......
Page 6: ...iv ...
Page 26: ...xxiv ...
Page 102: ...2 48 Configuring Username and Password Security Password Recovery ...
Page 204: ...4 72 Web and MAC Authentication Client Status ...
Page 550: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 612: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 734: ...14 44 Configuring and Monitoring Port Security Operating Notes for Port Security ...
Page 756: ...16 8 Key Management System Configuring Key Chain Management ...
Page 776: ...20 Index web server proxy 14 42 webagent access 6 6 wildcard See ACL wildcard See ACL ...
Page 777: ......