W
EB
C
ONFIGURATION
S
OFTWARE
R
EVISED
2018-09-21
S
ECURITY
D
RAWING
N
O
. LP0991-G
2-95
N-Tron
®
Series NT24K
®
Software Manual
2.22.2.4
Port
Security
‐
Single
MAC
Single MAC is a port security mode that allows a port to lock on a dynamically learned MAC address. The first MAC
address to be learned and processed by the port will be locked in and any further traffic will be blocked as an
intruder. The locking of the address is not dependent on switching the port security status to Locked. This feature
helps in providing security for ports that may only have a single device plugged into the switch. The Single MAC
address is not persistent following a reboot. The Single MAC will remain locked until a reboot upon which time a
new MAC address will be learned and assigned as the new Single MAC entry.
Single MAC can be configured per port from the Port Security Configuration page. Manually added MAC
addresses are not allowed to be assigned to a port designated as Single MAC. If a port is enabled under port
security and then changed to Single MAC all learned addresses will be cleared and the next MAC address that
comes in will be the new Single MAC address.
Single MAC addresses reset anytime the port security status is changed to Learning. Single MAC addresses are
persistent when port security status is changed from Learning or Locked to Disabled and then back to Locked.
Single MAC limitations include; intruders on the Single MAC port cannot be manually authorized, and new
addresses cannot be manually added to a Single MAC port.
2.22.3
Radius
Server
Configuration
Information
The NT24k takes advantage of Vendor Specific Attributes (VSA) as defined in section 5.26 of RFC 2865 so that
multiple user levels can be authenticated using a Radius server. The VSA is defined as follows:
The server and access list will need to be configured accordingly.
Vendor ID
28381
Vendor ID
28381
Attribute Number
1
Attribute Format
string
Attribute Value
"AccessLevel:admin" or "AccessLevel:user"