181
NOTE:
•
This feature is available only on a SAP interface card in bridging mode.
•
On a port operating in either the
macAddressElseUserLoginSecure
mode or the
macAddressElseUserLoginSecureExt
mode, intrusion protection is triggered only after both MAC
authentication and 802.1X authentication for the same frame fail.
Enabling port security traps
configure the port security module to send traps for the following categories of events:
•
addresslearned
—Learning of new MAC addresses.
•
dot1xlogfailure/dot1xlogon/dot1xlogoff
—802.1X authentication failure, success, and 802.1X user
logoff.
•
ralmlogfailure
/
ralmlogon/ralmlogoff
—MAC authentication failure, MAC authentication user logon,
and MAC authentication user logoff.
•
intrusion
—Detection of illegal frames.
To enable port security traps:
To do…
Command…
Remarks
1.
Enter system view.
system-view
—
2.
Enable port security traps.
port-security trap
{
addresslearned
|
dot1xlogfailure
|
dot1xlogoff
|
dot1xlogon
|
intrusion
|
ralmlogfailure
|
ralmlogoff
|
ralmlogon
}
Required.
By default, port security traps are
disabled.
Configuring secure MAC addresses
Secure MAC addresses never age out or get lost if saved before the device restarts. In a VLAN, a secure
MAC address can be added to only one port.
Secure MAC addresses can be the following types:
•
Learned by a port operating in
autoLearn
mode.
•
Manually configured at the command line interface or in the MIB.
When the maximum number of secure MAC addresses is reached, no more can be added. The port
allows only frames sourced from secure MAC addresses to pass through.
Configuration prerequisites
•
Enable port security.
•
Set the maximum number of secure MAC addresses on the port.
•
Set the port security mode to
autoLearn
.