![Alcatel OmniSwitch 6624 Скачать руководство пользователя страница 59](http://html1.mh-extra.com/html/alcatel/omniswitch-6624/omniswitch-6624_network-configuration-manual_2891390059.webp)
Configuring Learned Port Security
Sample Learned Port Security Configuration
OmniSwitch 6624/6648 Network Configuration Guide
April 2004
page 3-3
Sample Learned Port Security Configuration
This section provides a quick tutorial that demonstrates the following tasks:
•
Enabling LPS on a set of switch ports.
•
Defining the maximum number of learned MAC addresses allowed on an LPS port.
•
Defining the time limit in which source learning is allowed on all LPS ports.
•
Selecting a method for handling unauthorized traffic received on an LPS port.
Note that LPS is supported on 10/100 and gigabit Ethernet fixed, mobile, tagged and authenticated ports.
Link aggregate and tagged (trunked) link aggregate ports are not eligible for LPS monitoring and control.
1
Enable LPS on ports 6 through 12 on slot 3, 4, and 5 using the following command:
-> port-security 3/6-12 4/6-12 5/6-12 enable
2
Set the total number of learned MAC addresses allowed on the same ports to 25 using the following
command:
-> port-security 3/6-12 4/6-12 5/6-12 maximum 25
3
Configure the amount of time in which source learning is allowed on all LPS ports to 30 minutes using
the following command:
-> port-security shutdown 30
4
Select
shutdown
for the LPS violation mode using the following command:
-> port-security 3/6-12 4/6-12 5/6-12 violation shutdown
Note.
Optional
. To verify LPS port configurations, use the
show port-security
. For example:
-> show port-security
Port Security MaxMacs Violation
LowMac
HighMac
IndividualMac
MacType
----+--------+-------+---------+-----------------+-------------------+-----------------+-----------
2/2
enabled
25
restrict
00:20:95:00:00:10
00:20:95:00:00:20
4/8
enabled
100
shutdown
00:00:00:00:00:00
ff:ff:ff:ff:ff:ff
00:da:92:3a:59:0c configured
6/1
enabled
10
shutdown
00:00:00:00:00:00
ff:ff:ff:ff:ff:ff
00:da:92:4b:6a:1d
dynamic
00:da:92:5c:7b:2e
dynamic
6/5
enabled
100
restrict 00:00:00:00:00:00
ff:ff:ff:ff:ff:ff
00:da:92:00:1a:20
configured
To verify the new source learning time limit value, use the
show port-security shutdown
command. For
example:
-> show port-security shutdown
LPS Shutdown = 30
Содержание OmniSwitch 6624
Страница 1: ...Part No 060179 10 Rev C April 2004 OmniSwitch 6624 6648 Network Configuration Guide www alcatel com...
Страница 22: ...Contents xxii OmniSwitch 6624 6648 Network Configuration Guide April 2004...
Страница 174: ...Verifying 802 1Q Configuration Configuring 802 1Q page 9 12 OmniSwitch 6624 6648 Network Configuration Guide April 2004...
Страница 264: ...Verifying the RIP Configuration Configuring RIP page 13 16 OmniSwitch 6624 6648 Network Configuration Guide April 2004...
Страница 276: ...Verifying the RDP Configuration Configuring RDP page 14 12 OmniSwitch 6624 6648 Network Configuration Guide April 2004...