![Atop EH9711 Series Скачать руководство пользователя страница 176](http://html1.mh-extra.com/html/atop/eh9711-series/eh9711-series_user-manual_3004814176.webp)
Industrial Managed
Ethernet Switch – EH9711
User Manual
Page
176
of
223
Check
Auto-refresh box
to refresh the page automatically. Automatic refresh occurs every 3 seconds. Click
Refresh button
to refresh the page immediately.
3.5.1.2
Port Security Details
This page shows the MAC addresses secured by the Port Security module. Port Security is a module with no direct
configuration. Configuration comes indirectly from other modules - the user modules. When a user module has enabled port
security on a port, the port is set-up for software-based learning. In this mode, frames from unknown MAC addresses are passed
on to the port security module, which in turn asks all user modules whether to allow this new MAC address to forward or block
it. For a MAC address to be set in the forwarding state, all enabled user modules must unanimously agree on allowing the
MAC address to forward. If only one chooses to block it, it will be blocked until that user module decides otherwise.
Figure 3.23 Webpage to Monitor Port Security Port Status All Ports
Table 3.17 Monitoring Descriptions of Port Security Port Status All Ports
reached.
Shut down
: The Port Security service is administratively enabled and the port is shut
down. No MAC addresses can be learned on the port until it is administratively re-
opened by administratively taking the port down and then back up on the
"Configuration→Ports" page. Alternatively, the switch may be booted or reconfigured
Port Security-wise.
MAC Count
(Current, Violating,
Limit)
The three columns indicate the number of currently learned MAC addresses (forwarding
as well as blocked), the number of violating MAC address (only counting in Restrict
mode) and the maximum number of MAC addresses that can be learned on the port,
respectively.
If no user modules are enabled on the port, the Current column will show a dash (-).
If Port Security is not administratively enabled on the port, the Violating and Limit
columns will show a dash (-)..
Label
Description
Delete
Click to remove this particular MAC addresses from MAC address table. The button is only clickable if
the entry type is Dynamic. Use the "Configuration→Security→Port Security→MAC Addresses" page to
remove Static and Sticky entries.
Port
If all ports are shown (can be selected through the drop-down box on the top right), this one shows the
port to which the MAC address is bound.
MAC
Address &
VLAN ID
The MAC address and VLAN ID that is seen on this port. If no MAC addresses are learned, a single row
stating "No MAC addresses attached" is displayed.
Type
Indicates the type of entry. Takes one of three values:
Dynamic
: The entry is learned through learn frames coming to the Port Security module while
the port in question is not in sticky mode.
Static
: The entry is entered by the end-user through management. Entry is not subject to aging.
Sticky
: When the port is in sticky mode, all entries that would otherwise have been learned as
dynamic are learned as sticky.
Sticky entries are part of the running-config and can therefore be saved to startup-config. An
important aspect of sticky MAC addresses is that they survive link changes (in contrast to
Dynamic, which will have to be learned again). They also survive reboots if running-config is
saved to startup-config.