S1700 Managed Series Ethernet Switches
Web User Manual
9 Security
Issue 05 (2012-10-25)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
139
Figure 9-21
Configure Port Security for Interface
Table 9-15
Parameters of Configuring Port Security
Item
Description
Interface Name
Display interface number.
Port Security
Enable or Disable port security on the interface.
Security Action
Protect: When the number of learned MAC address reaches the
limitation number of interface, the interface will drop the message
whose source address is not included in MAC table.
Restrict: When the number of the learned MAC address reaches the
limitation number of interface, the interface will drop the message
whose source address is not included in MAC table, and record it in
the system log.
Shutdown: When the number of the learned MAC address reaches
the limitation number of interface, the interface will execute
Shutdown operation, and record it in the system log.
Static Address Aging
Enable or Disable static address aging.
Sticky Learning
Sticky is used to convert the dynamic MAC address learned on the
interface to static MAC address. When the Maximum number of
MAC reaches the upper limitation, the interface will not learn new
MAC address, and only allow the security MAC to communicate
with the switch, which not only avoids the lost dynamic Mac‟s
re-learning after the device reboots, but also prevents the untrusted
MAC host from communicating with the switch through the
interface.