data:image/s3,"s3://crabby-images/26528/26528def0c5560ace4f84e684717dd0a8c579b06" alt="OmniSwitch os6900 Network Configuration Manual Download Page 815"
Configuring Learned Port Security
Configuring Learned Port Security
OmniSwitch AOS Release 7 Network Configuration Guide
June 2013
page 31-15
Configuring an Authorized MAC Address Range
By default, each LPS port is set to a range of 00:00:00:00:00:00–ff:ff:ff:ff:ff:ff, which includes all MAC
addresses. If this default is not changed, then addresses received on LPS ports are subject only to the
learning window time and restrictions on the maximum number of MAC addresses allowed for the port.
All MAC addresses that fall within the default or a specific configured range of addresses are dynami-
cally learned as bridged MAC addresses (up to the maximum of bridged addresses allowed). If a MAC
address falls outside of the specified range, the address is dynamically learned as a filtered MAC address
(up to the maximum of filtered addresses allowed).
To configure a source MAC address range for an LPS port, use the
command.
For example, the following command configures a MAC address range for port 1 on slot 4:
-> port-security port 4/1 mac-range low 00:20:da:00:00:10 high 00:20:da:00:00:50
The following command examples configure a MAC address range for a range of ports:
-> port-security port 4/1-5 mac-range low 00:20:da:00:00:10 high
00:20:da:00:00:50
-> port-security port 2/1-4 mac-range low 00:20:d0:59:0c:9a high
00:20:d0:59:0c:9f
To restore the range to the default values, use the
port-security
parameter followed by the
port
keyword
and
slot/port
designation of the port and the
mac-range
. The MAC address range is restored to
00:00:00:00:00:00 and ff:ff:ff:ff:ff:ff when the
low
and
high
MAC addresses are excluded. For example,
the following command sets the authorized MAC address range to the default values for port 12 of slot 4:
-> port-security port 4/12 mac-range
In addition, specifying a low end MAC and a high end MAC is optional. If either one is not specified, the
default value is used. For example, the following commands set the authorized MAC address range on the
specified ports to 00:da:25:59:0c:10–ff:ff:ff:ff:ff:ff and 00:00:00:00:00:00–00:da:25:00:00:9a:
-> port-security port 2/8 mac-range low pp:da:25:59:0c
-> port-security port 2/10 mac-range high 00:da:25:00:00:9a
Refer to the
OmniSwitch CLI Reference Guide
for more information about this command.