14-40
Configuring and Monitoring Port Security
Reading Intrusion Alerts and Resetting Alert Flags
Figure 14-22.Example of the Intrusion Log with Multiple Entries for the Same Port
The above example shows three intrusions for port A1. Since the switch can
show only one uncleared intrusion per port, the older two intrusions in this
example have already been cleared by earlier use of the
clear intrusion-log
or
the
port-security <
port-list
> clear-intrusion-flag
command. (The intrusion log
holds up to 20 intrusion records, and deletes intrusion records only when the
log becomes full and new intrusions are subsequently added.) The “
prior to
”
text in the record for the third intrusion means that a switch reset occurred
at the indicated time and that the intrusion occurred prior to the reset.
To clear the intrusion from port A1 and enable the switch to enter any
subsequent intrusion for port A1 in the Intrusion Log, execute the port-security
clear-intrusion-flag
command. If you then re-display the port status screen, you
will see that the Intrusion Alert entry for port A1 has changed to “
No
”.
(Executing
show port-security intrusion-log
again will result in the same display
as above, and does not include the Intrusion Alert status.)
HP Switch(config)# port-security a1 clear-intrusion-flag
HP Switch(config)# show interfaces brief
HP Switch(config)# show port-security intrusion-log
Status and Counters - Intrusion Log
Port MAC Address Date / Time
----- ------------- --------------------------
1 080009-e93d4f 03/07/11 21:09:34
1 080009-21ae84 03/07/11 17:26:27
1 080009-e93d4f prior to 03/07/11 17:18:43
0 secs
0 secs
35 mins
43 mins
4 hours
Dates and Times of
Intrusions
MAC Address of latest
Intruder on Port A1
Earlier intrusions on
port A1 that have
already been cleared
(that is, the Alert Flag
has been reset at least
twice before the most
recent intrusion
occurred.
Summary of Contents for HP ProCurve Series 6600
Page 2: ......
Page 6: ...iv ...
Page 26: ...xxiv ...
Page 102: ...2 48 Configuring Username and Password Security Password Recovery ...
Page 204: ...4 72 Web and MAC Authentication Client Status ...
Page 550: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 612: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 734: ...14 44 Configuring and Monitoring Port Security Operating Notes for Port Security ...
Page 756: ...16 8 Key Management System Configuring Key Chain Management ...
Page 776: ...20 Index web server proxy 14 42 webagent access 6 6 wildcard See ACL wildcard See ACL ...
Page 777: ......