178
Setting the maximum number of secure MAC
addresses
The maximum number of users a port supports in a port security mode is determined by the maximum
number of secure MAC addresses or the maximum number of authenticated users that the security mode
supports, whichever is smaller.
By setting the maximum number of MAC addresses allowed on a port, implement the following control:
•
Control the number of secure MAC addresses that a port can learn for port security.
•
Control the maximum number of users who are allowed to access the network through the port.
To set the maximum number of secure MAC addresses allowed on a port:
To do…
Command…
Remarks
1.
Enter system view.
system-view
—
2.
Enter interface view.
interface
interface-type
interface-number
—
3.
Set the maximum number of secure MAC
addresses allowed on a port.
port-security max-mac-count
count-value
Required
Not limited by default
NOTE:
•
This feature is available only on a SAP interface card in bridging mode.
•
This configuration is independent of the MAC learning limit described in MAC address table
configuration
in the Layer 2—LAN Switching Configuration Guide.
Setting the port security mode
Configuration prerequisites
Before you set the port security mode, complete the following tasks:
•
On the port, disable 802.1X, set the port access control method to
macbased
, and set the port
authorization mode to
auto
.
•
Disable MAC authentication on the port.
The requirements above must be all met. Otherwise, an error message appears when you set a security
mode on the port. After setting a port security mode on a port, you cannot change any of the
configurations above.
•
Before you configure the port to operate in
autoLearn
mode, set the maximum number of secure
MAC addresses allowed on a port.
NOTE:
•
With port security disabled, configure a port security mode, but your configuration does not take
effect.
•
You cannot change the port security mode of a port with users online.