Raisecom
ISCOM2600G-HI (A) Series Configuration Guide
10 Security
Raisecom Proprietary and Confidential
Copyright © Raisecom Technology Co., Ltd.
403
10.1.7 Maintenance
Maintain the ISCOM2600G-HI series switch as below.
Command
Description
Raisecom(config)#clear filter statistics interface
{
interface-type interface-number
| vlan
vlan-id
}
{ egress | ingress } [ access-list
acl-number
]
Clear statistics on
ACL filter
configurations.
10.2 Port security MAC
10.2.1 Introduction
Port security MAC is used for the switching device on the edge of the network user side. It
can ensure security of accessed data on an interface, and control the incoming packets
according to the source MAC address.
You can enable port security MAC to limit and distinguish which users can access the
network through secure interfaces. Only secure MAC addresses can access the network,
unsecure MAC addresses will be dealt with as configured interface access violation mode.
Secure MAC address classification
Secure MAC addresses supported by the device are divided into the following three categories:
Static secure MAC address
The static secure MAC address is configured by user on secure interface manually; this MAC
address will take effect when port security MAC is enabled. Static secure MAC address does
not age and supports loading configuration.
Dynamic secure MAC address
The dynamic secure MAC address is learnt by the device. You can configure the learnt MAC
address to secure MAC address in the range of the maximum number of learnt MAC address.
The dynamic secure MAC addresses are aged and does not support configuration load.
The dynamic secure MAC address can be converted to the sticky secure MAC address if
necessary, so as not to be aged and supports auto-loading.
Sticky secure MAC address
The sticky secure MAC address is generated from the manual configuration of user in secure
interface or converted from dynamic secure MAC address. Different from static secure MAC
address, the sticky secure MAC address needs to be used in conjunction with sticky learning:
When sticky learning is enabled, the sticky secure MAC address will take effect and this
address will not be aged.
When sticky learning is disabled, the sticky secure MAC address will become invalid
and be saved only in the system.