9-13
Configuring and Monitoring Port Security
Port Security Command Options and Operation
ProCurve(config)# port-security a1 learn-mode static
mac-address 0c0090-123456 action send-disable
This example configures port A5 to:
■
Allow two MAC addresses, 00c100-7fec00 and 0060b0-889e00, as the
authorized devices.
■
Send an alarm to a management station if an intruder is detected on
the port.
ProCurve(config)# port-security a5 learn-mode static
address-limit 2 mac-address 00c100-7fec00 0060b0-889e00
action send-alarm
If you manually configure authorized devices (MAC addresses) and/or an
alarm action on a port, those settings remain unless you either manually
change them or reset the switch to its factory-default configuration. You can
“turn off” device authorization on a port by configuring the port to
continuous
Learn Mode, but subsequently reconfiguring the port to
static
Learn Mode
restores the configured device authorization.
Learn-Mode Configured.
This option allows only MAC addresses specifi-
cally configured with
learn-mode configured mac-address <
mac-address
>
, and
does not automatically learn non-specified MAC addresses learned from the
network. This example configures port A1 to:
■
Allow only a MAC address of 0c0090-123456 as the authorized device
■
Reserve the option for adding two more specified MAC addresses at
a later time without having to change the address-limit setting.
■
Send an alarm to a management station if an intruder is detected on
the port.
ProCurve(config)# port-security A1 learn-mode configured
mac-address 0c0090-123456 address-limit 3 action send-
disable
Adding a MAC Address to an Existing Port List
To simply add a device (MAC address) to a port’s existing Authorized
Addresses list, enter the port number with the
mac-address
parameter and the
device’s MAC address.
This assumes that Learn Mode is either
static
or
configured
and the Authorized Addresses list is not already full
(as deter-
Summary of Contents for ProCurve 2510-24
Page 1: ...Access Security Guide 2510 www procurve com ProCurve Switches Q 11 XX 2510 24 U 11 XX 2510 48 ...
Page 2: ......
Page 3: ...ProCurve Series 2510 Switches Access Security Guide July 2008 ...
Page 26: ...1 10 Getting Started Need Only a Quick Start ...
Page 104: ...4 30 TACACS Authentication Configuring TACACS on the Switch ...
Page 144: ...5 40 RADIUS Authentication Authorization and Accounting Messages Related to RADIUS Operation ...
Page 174: ...6 30 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Page 196: ...7 22 Configuring Secure Socket Layer SSL Common Errors in SSL Setup ...
Page 294: ...9 40 Configuring and Monitoring Port Security Configuring Protected Ports ...
Page 308: ...10 14 Using Authorized IP Managers Operating Notes ...
Page 316: ...8 Index ...
Page 317: ......