data:image/s3,"s3://crabby-images/45507/4550786fbb5e3d5db4049e36ac4b90a674d4405c" alt="OmniSwitch os6900 Network Configuration Manual Download Page 813"
Configuring Learned Port Security
Configuring Learned Port Security
OmniSwitch AOS Release 7 Network Configuration Guide
June 2013
page 31-13
The no MAC address aging option is best used in combination with the option that converts dynamic
addresses to static address. Enabling both of these options ensures that no learned MAC addresses will age
out before or after the learning window closes.
By default, the no MAC address aging status is disabled. To enable this option for the learning window,
use the following command:
-> port-security learning-window no-aging enable
To disable this option for the learning window, use the following command:
-> port-security learning-window no-aging disable
Converting Dynamic MAC Addresses to Static MAC Addresses
When the learning window time expires, all the dynamic and pseudo-static MAC addresses learned on the
LPS ports start to age out. The
convert-to-static
parameter option of the
port-security learning-window
command is used to specify whether or not these MAC addresses are converted to static addresses when
the learning window time period ends.
By default, converting dynamic MACs to static MACs is disabled. To enable this option for the learning
window, use the following command:
-> port-security learning-window 30 convert-to-static enable
The following command disables this option for the learning window:
-> port-security learning-window 30 convert-to-static disable
Note
. The number of converted static MAC addresses cannot exceed the maximum number of MAC
addresses allowed on the LPS ports.
Starting the Learning Window at Boot Up
By default, the
boot-up
option is enabled when the learning window time is configured. This option speci-
fies that whenever the switch reboots, the learning window time period will automatically restart at the
time the reboot occurs.
To disable this functionality, use the
boot-up disable
parameter with the
port-security learning-window
command. For example:
-> port-security learning-window boot-up disable
To enable this functionality, use the
boot-up enable
parameter with the
port-security learning-window
command. For example:
-> port-security learning-window boot-up disable
Note.
After the
boot-up
option is enabled (either by default or explicitly configured), perform the
write
memory
command to save the
port-security learning-window
command to the switch configuration
(
boot.cfg
file). This will ensure that the learning window will automatically start when the switch reboots.