
OmniSwitch AOS Release 7 Network Configuration Guide
June 2013
page 31-1
31 Configuring Learned
Port Security
Learned Port Security (LPS) provides a mechanism for authorizing source learning of MAC addresses on
Ethernet ports. The only types of Ethernet ports that LPS does not support are link aggregate and 802.1Q
trunked link aggregate ports. Using LPS to control source MAC address learning provides the following
benefits:
•
A configurable source learning time limit that applies to all LPS ports.
•
A configurable limit on the number of MAC addresses (bridged and filtered) allowed on an LPS port.
•
Dynamic configuration of a list of authorized source MAC addresses.
•
Static configuration of a list of authorized source MAC addresses.
•
Three methods for handling unauthorized traffic: administratively disable the LPS port, stop all traffic
on the port (port remains up), or only block traffic that violates LPS criteria.
In This Chapter
This chapter provides an over of the LPS feature and describes how to configure LPS parameters through
the Command Line Interface (CLI). CLI commands are used in the configuration examples; for more
details about the syntax of commands, see the
OmniSwitch CLI Reference Guide
.
The following information and procedures are included in this chapter:
•
“Learned Port Security Specifications” on page 31-2
.
•
“Learned Port Security Defaults” on page 31-2
•
“Sample Learned Port Security Configuration” on page 31-3
•
“Learned Port Security Overview” on page 31-5
.
•
“Configuring Learned Port Security” on page 31-10
.
•
“Displaying Learned Port Security Information” on page 31-17
.
For more information about source MAC address learning, see