![HP HP ProCurve Series 6600 Access Security Manual Download Page 728](http://html.mh-extra.com/html/hp/hp-procurve-series-6600/hp-procurve-series-6600_access-security-manual_163101728.webp)
14-38
Configuring and Monitoring Port Security
Reading Intrusion Alerts and Resetting Alert Flags
Figure 14-20. Example of the Intrusion Log Display
The example in Figure 7-11 shows two intrusions for port A3 and one
intrusion for port A1. In this case, only the most recent intrusion at port
A3 has not been acknowledged (reset). This is indicated by the following:
•
Because the Port Status screen (figure 14-19 on page 14-37) does
not indicate an intrusion for port A1, the alert flag for the intru-
sion on port A1 has already been reset.
•
Since the switch can show only one uncleared intrusion per port,
the alert flag for the older intrusion for port A3 in this example
has also been previously reset.
(The intrusion log holds up to 20 intrusion records and deletes an
intrusion record only when the log becomes full and a new intrusion
is subsequently detected.)
Note also that the “
prior to
” text in the record for the earliest intrusion
means that a switch reset occurred at the indicated time and that the
intrusion occurred prior to the reset.
3.
To acknowledge the most recent intrusion entry on port A3 and enable
the switch to enter a subsequently detected intrusion on this port, type
[R]
(for
Reset alert flags
). (Note that if there are unacknowledged intrusions
on two or more ports, this step resets the alert flags for all such ports.)
If you then re-display the port status screen, you will see that the Intrusion
Alert entry for port A3 has changed to “
No
”. That is, your evidence that the
Intrusion Alert flag has been acknowledged (reset) is that the Intrusion Alert
column in the port status display no longer shows “
Yes
” for the port on which
the intrusion occurred (port A3 in this example). (Because the Intrusion Log
provides a history of the last 20 intrusions detected by the switch, resetting
the alert flags does not change its content. Thus, displaying the Intrusion Log
again will result in the same display as in figure 14-20, above.)
System Time of Intrusion on Port
A3
MAC Address
of Intruding
Device on
Port A3
Indicates this intrusion on port
A3 occurred prior to a reset
(reboot) at the indicated time
Summary of Contents for HP ProCurve Series 6600
Page 2: ......
Page 6: ...iv ...
Page 26: ...xxiv ...
Page 102: ...2 48 Configuring Username and Password Security Password Recovery ...
Page 204: ...4 72 Web and MAC Authentication Client Status ...
Page 550: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 612: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 734: ...14 44 Configuring and Monitoring Port Security Operating Notes for Port Security ...
Page 756: ...16 8 Key Management System Configuring Key Chain Management ...
Page 776: ...20 Index web server proxy 14 42 webagent access 6 6 wildcard See ACL wildcard See ACL ...
Page 777: ......