Procedure
Step 1
Run:
system-view
The system view is displayed.
Step 2
Run:
interface
interface-type
interface-number
The interface view is displayed.
Step 3
Run:
port-security enable
Port security is enabled.
By default, port security is disabled on an interface.
Step 4
(Optional) Run:
port-security max-mac-num
max-number
The limit on the number of secure dynamic MAC addresses is set.
By default, the limit on the number of secure dynamic MAC addresses is 1.
Step 5
(Optional) Run:
port-security protect-action
{
protect
|
restrict
|
shutdown
}
The protection action is configured.
The default action is
restrict
.
The protection actions are as follows:
l
protect
: discards packets with new source MAC addresses when the number of learned MAC
addresses reaches the limit.
l
restrict
: discards packets with new source MAC addresses and sends an alarm when the
number of learned MAC addresses exceeds the limit.
l
shutdown
: set the interface status to
error down
and sends an alarm when the number of
learned MAC addresses exceeds the limit.
By default, an interface cannot automatically restore to Up state after it is shut down. To
restore the interface, run the
undo shutdown
command on the interface in sequence.
Alternatively, run the
restart
command on the interface to restart the interface.
Step 6
(Optional) Run:
port-security aging-time
time
The aging time of secure dynamic MAC addresses is set.
By default, secure dynamic MAC addresses will not be aged out.
----End
Huawei AR530&AR550 Series Industrial Switch Routers
Configuration Guide - Ethernet Switching
1 MAC Address Table Configuration
Issue 01 (2014-11-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
15