9-34
Configuring and Monitoring Port Security
Reading Intrusion Alerts and Resetting Alert Flags
Figure 9-17. Example of the Intrusion Log with Multiple Entries for the Same Port
The above example shows three intrusions for port A1. Since the switch can
show only one uncleared intrusion per port, the older two intrusions in this
example have already been cleared by earlier use of the
clear intrusion-log
or
the
port-security <
port-list
> clear-intrusion-flag
command. (The intrusion log
holds up to 20 intrusion records, and deletes intrusion records only when the
log becomes full and new intrusions are subsequently added.) The “
prior to
”
text in the record for the third intrusion means that a switch reset occurred
at the indicated time and that the intrusion occurred prior to the reset.
To clear the intrusion from port A1 and enable the switch to enter any
subsequent intrusion for port A1 in the Intrusion Log, execute the port-security
clear-intrusion-flag
command. If you then re-display the port status screen, you
will see that the Intrusion Alert entry for port A1 has changed to “
No
”.
(Executing
show port-security intrusion-log
again will result in the same display
as above, and does not include the Intrusion Alert status.)
ProCurve(config)# port-security a1 clear-intrusion-flag
ProCurve(config)# show interfaces brief
Figure 9-18. Example of Port Status Screen After Alert Flags Reset
For more on clearing intrusions, see “Note on Send-Disable Operation” on
page 9-30.
Dates and Times of
Intrusions
MAC Address of latest
Intruder on Port A1
Earlier intrusions on port
A1 that have already been
cleared (that is, the Alert
Flag has been reset at
least twice before the
most recent intrusion
occurred.
Intrusion Alert on port A1 is now cleared.
Summary of Contents for ProCurve 2510-24
Page 1: ...Access Security Guide 2510 www procurve com ProCurve Switches Q 11 XX 2510 24 U 11 XX 2510 48 ...
Page 2: ......
Page 3: ...ProCurve Series 2510 Switches Access Security Guide July 2008 ...
Page 26: ...1 10 Getting Started Need Only a Quick Start ...
Page 104: ...4 30 TACACS Authentication Configuring TACACS on the Switch ...
Page 144: ...5 40 RADIUS Authentication Authorization and Accounting Messages Related to RADIUS Operation ...
Page 174: ...6 30 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Page 196: ...7 22 Configuring Secure Socket Layer SSL Common Errors in SSL Setup ...
Page 294: ...9 40 Configuring and Monitoring Port Security Configuring Protected Ports ...
Page 308: ...10 14 Using Authorized IP Managers Operating Notes ...
Page 316: ...8 Index ...
Page 317: ......