1-9
z
blockmac
: Adds the source MAC addresses of illegal frames to the blocked MAC addresses list
and discards frames with blocked source MAC addresses. A blocked MAC address is restored to
normal after being blocked for three minutes, which is fixed and cannot be changed.
z
disableport
: Disables the port permanently.
z
disableport-temporarily
: Disables the port for a specified period of time. Use the
port-security
timer disableport
command to set the period.
Follow these steps to configure the intrusion protection feature:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter interface view
interface
interface-type
interface-number
—
Configure the intrusion
protection feature
port-security intrusion-mode
{
blockmac
|
disableport
|
disableport-temporarily
}
Required
By default, intrusion protection
is disabled.
Return to system view
quit
—
Set the silence timeout during
which a port remains disabled
port-security timer
disableport
time-value
Optional
20 seconds by default
On a port operating in either the macAddressElseUserLoginSecure mode or the
macAddressElseUserLoginSecureExt mode, intrusion protection is triggered only after both MAC
authentication and 802.1X authentication for the same frame fail.
Configuring Trapping
The trapping feature enables a device to send trap information in response to four types of events:
z
addresslearned
: Learning of a new address.
z
dot1xlogfailure/dot1xlogon/dot1xlogoff
: 802.1x authentication failure/successful 802.1x
authentication/802.1x user logoff.
z
ralmlogfailure
/
ralmlogoff
: MAC authentication failure/MAC authentication user logoff.
z
intrusion
: Finding of illegal frames.
Follow these steps to configure port security trapping:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enable port security traps
port-security trap
{
addresslearned
|
dot1xlogfailure
|
dot1xlogoff
|
dot1xlogon
|
intrusion
|
ralmlogfailure
|
ralmlogoff
|
ralmlogon
}
Required
By default, no port security trap
is enabled.
Содержание S7906E - Switch
Страница 82: ...1 4 DeviceA interface tunnel 1 DeviceA Tunnel1 service loopback group 1...
Страница 200: ...1 11 DeviceB display vlan dynamic No dynamic vlans exist...
Страница 494: ...ii Displaying and Maintaining Tunneling Configuration 1 45 Troubleshooting Tunneling Configuration 1 45...
Страница 598: ...ii...
Страница 1757: ...4 9...
Страница 1770: ...6 4...
Страница 2017: ...2 11 Figure 2 3 SFTP client interface...
Страница 2062: ...i Table of Contents 1 URPF Configuration 1 1 URPF Overview 1 1 What is URPF 1 1 How URPF Works 1 1 Configuring URPF 1 2...
Страница 2238: ...1 16 DeviceA cfd linktrace service instance 1 mep 1001 target mep 4002...
Страница 2442: ...2 4 Set the interval for sending Syslog or trap messages to 20 seconds Device mac address information interval 20...