![Nortel 2526T Configuration Download Page 175](http://html1.mh-extra.com/html/nortel/2526t/2526t_configuration_1707291175.webp)
Configuring MAC address-based security
175
—End—
With Web access enabled, the switch can support a maximum of four
concurrent Web page users. Two predefined user levels are available, and
each user level has a corresponding username and password.
Table 82 "User levels and access levels" (page 175)
shows an example of
the two predefined user levels available and their access level within the
Web-based management user interface.
Table 82
User levels and access levels
User level
User name for
each level
Password for each
user level
Access Level
Read-only
RO
XXXXXXXX
Read only
Read/write
RW
XXXXXXXX
Full read/write
access
Configuring MAC address-based security
The MAC address-based security system lets you specify a range of system
responses to unauthorized network access to your switch by using the
Web-based management system.
The system response can range from sending a trap to disabling the port.
The network access control is based on the MAC Source Addresses (SAs)
of the authorized stations. You can specify a list of up to 448 MAC SAs that
are authorized to access the switch. You can also specify the ports that
each MAC SA is allowed to access. The options for allowed MAC SA port
access include: NONE, ALL, and single or multiple ports that are specified
in a list, for example, one to four, six, nine, and so on. You must also include
the MAC SA of any router connected to any secure ports.
After the switch software detects an SA security violation, the response can
be to send a trap, turn on Destination Address (DA) filtering for all SAs,
disable the specific port, or any combination of these three options.
You can also configure the Ethernet Routing Switch 2500 Series to drop
all packets that have a specified MAC Destination Address (DA). You can
create a list of up to 10 MAC DAs that you want to filter. The packet with
the specified MAC DA is dropped regardless of the ingress port, Source
Address (SA) intrusion, or VLAN membership.
Nortel Ethernet Routing Switch 2500 Series
Security — Configuration and Management
NN47215-505 (323165-B)
02.01
Standard
4.1
19 November 2007
Copyright © 2007, Nortel Networks
.
Summary of Contents for 2526T
Page 227: ......