Configuring and Monitoring Port Security
Reading Intrusion Alerts and Resetting Alert Flags
To clear the intrusion from port A1 and enable the switch to enter any
subsequent intrusion for port A1 in the Intrusion Log, execute the port-security
clear-intrusion-flag
command. If you then re-display the port status screen, you
will see that the Intrusion Alert entry for port A1 has changed to “
No
”.
(Executing
show port-security intrusion-log
again will result in the same display
as above, and does not include the Intrusion Alert status.)
ProCurve(config)# port-security a1 clear-intrusion-flag
ProCurve(config)# show interfaces brief
Intrusion Alert on port A1 is now
Figure 13-17.Example of Port Status Screen After Alert Flags Reset
For more on clearing intrusions, see “Note on Send-Disable Operation” on
page 13-35
Using the Event Log To Find Intrusion Alerts
The Event Log lists port security intrusions as:
W MM/DD/YY HH:MM:SS FFI: port A3 — Security Violation
where “
W
” is the severity level of the log entry and
FFI
is the system module
that generated the entry. For further information, display the Intrusion Log,
as shown below.
From the CLI.
Type the
log
command from the Manager or Configuration
level.
Syntax:
log <
search-text
>
For
<
search-text
>
, you can use
ffi
,
security
, or
violation
. For example:
13-39
Summary of Contents for PROCURVE 2910AL
Page 1: ...Access Security Guide ProCurve Switches W 14 03 2910al www procurve com ...
Page 2: ......
Page 3: ...HP ProCurve 2910al Switch February 2009 W 14 03 Access Security Guide ...
Page 84: ...Configuring Username and Password Security Front Panel Security 2 36 ...
Page 156: ...TACACS Authentication Operating Notes 4 30 ...
Page 288: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup 8 22 ...
Page 416: ...Configuring Advanced Threat Protection Using the Instrumentation Monitor 10 28 ...
Page 572: ...Using Authorized IP Managers Operating Notes 14 14 ...
Page 592: ...12 Index ...
Page 593: ......