Chapter 13: Security Measures
Configuring Port Security
– 335 –
•
To configure the maximum number of address entries which can be
learned on a port, and then specify the maximum number of dynamic
addresses allowed. The switch will learn up to the maximum number of
allowed address pairs <source MAC address, VLAN> for frames
received on the port. When the port has reached the maximum number
of MAC addresses, the port will stop learning new addresses. The MAC
addresses already in the address table will be retained and will not be
aged out.
Note that you can manually add additional secure addresses to a port
using the Static Address Table (
•
When the port security state is changed from enabled to disabled, all
dynamically learned entries are cleared from the address table.
•
If port security is enabled, and the maximum number of allowed
addresses are set to a non-zero value, any device not in the address
table that attempts to use the port will be prevented from accessing the
switch.
•
If a port is disabled (shut down) due to a security violation, it must be
manually re-enabled from the Interface > Port > General page
(
•
A secure port has the following restrictions:
•
It cannot be used as a member of a static or dynamic trunk.
•
It should not be connected to a network interconnection device.
•
RSPAN and port security are mutually exclusive functions. If port
security is enabled on a port, that port cannot be set as an RSPAN
uplink port, source port, or destination port. Also, when a port is
configured as an RSPAN uplink port, source port, or destination
port, port security cannot be enabled on that port.
P
ARAMETERS
These parameters are displayed:
•
Port
– Port identifier.
•
Security Status
– Enables or disables port security on the port.
(Default: Disabled)
•
Port Status
– The operational status:
•
Secure/Down – Port security is disabled.
•
Secure/Up – Port security is enabled.
•
Shutdown – Port is shut down due to a response to a port security
violation.
•
Action
– Indicates the action to be taken when a port security violation
is detected:
Summary of Contents for SSE-G2252
Page 42: ...44 General IP Routing on page 627...
Page 603: ...Chapter 16 IP Configuration Setting the Switch s IP Address IP Version 6 609...
Page 883: ...Chapter 24 General Security Measures Port based Traffic Segmentation 894...
Page 989: ...Chapter 30 Congestion Control Commands Automatic Traffic Control Commands 1000 Console...
Page 1007: ...Chapter 33 Address Table Commands 1019...
Page 1137: ...Chapter 38 Quality of Service Commands 1150...