
BigIron RX Series Configuration Guide
947
53-1002253-01
Chapter
32
Using the MAC Port Security Feature
and Transparent Port Flooding
This chapter discusses the MAC Port Security and transparent port flooding features.
MAC Port Security
The MAC Port Security feature restricts unauthorized access to an interface by limiting and
identifying MAC addresses that are allowed to access an Ethernet interface on a device. You can
configure the BigIron RX with a limited number of “secure” MAC addresses on an interface. The
interface will forward only packets with source MAC addresses that match these secure addresses.
The secure MAC addresses can be specified manually (static), or the device can learn them
automatically (dynamic).
An interface can store up to the maximum number of secure MAC addresses. If the maximum
number of secure MAC addresses are learned and the interface receives a packet with a source
MAC address that is different from any of the secure learned MAC addresses, the address is
considered a security violation.
NOTE
The MAC Port Security feature applies only to Ethernet interfaces. It is not available on loopback,
virtual routing (ve) or other interface types.
Violation actions
When a security violation occurs, a Syslog entry is generated. In addition, the device takes one of
the following actions:
•
Shuts down the interface, either permanently or for a specified amount of time. This is the
default.
•
Drops packets from the unauthorized MAC address, but allows packets from the secure MAC
addresses. The interface remains enabled.
•
Denies the packet from the unauthorized MAC address, but allows packets from secure MAC
addresses. The interface remains enabled.
The secure MAC addresses are not flushed when an interface is disabled and brought up again.
The secure addresses can be kept secure permanently (the default), or can be configured to age
out, at which time they are no longer secure. You can configure the device to automatically save the
list of secure MAC addresses to the startup-config file at specified intervals, allowing addresses to
be kept secure across system restarts.
Содержание BigIron RX Series
Страница 100: ...24 BigIron RX Series Configuration Guide 53 1002253 01 Logging on through the Web Management Interface 2 ...
Страница 192: ...116 BigIron RX Series Configuration Guide 53 1002253 01 Configuring authentication method lists 4 ...
Страница 228: ...152 BigIron RX Series Configuration Guide 53 1002253 01 Enabling WAN PHY mode support 6 ...
Страница 312: ...236 BigIron RX Series Configuration Guide 53 1002253 01 Displaying IP information 7 ...
Страница 356: ...280 BigIron RX Series Configuration Guide 53 1002253 01 Resetting LLDP statistics 9 ...
Страница 402: ...326 BigIron RX Series Configuration Guide 53 1002253 01 Transparent firewall mode 11 ...
Страница 432: ...356 BigIron RX Series Configuration Guide 53 1002253 01 SuperSpan 12 ...
Страница 500: ...424 BigIron RX Series Configuration Guide 53 1002253 01 MRP CLI example 14 ...
Страница 580: ...504 BigIron RX Series Configuration Guide 53 1002253 01 Configuring multicast traffic engineering 18 ...
Страница 591: ...BigIron RX Series Configuration Guide 515 53 1002253 01 Displaying traffic reduction 19 ...
Страница 592: ...516 BigIron RX Series Configuration Guide 53 1002253 01 Displaying traffic reduction 19 ...
Страница 598: ...522 BigIron RX Series Configuration Guide 53 1002253 01 Viewing Layer 2 ACLs 20 ...
Страница 656: ...580 BigIron RX Series Configuration Guide 53 1002253 01 Trunk formation 22 ...
Страница 754: ...678 BigIron RX Series Configuration Guide 53 1002253 01 Displaying RIP filters 24 ...
Страница 814: ...738 BigIron RX Series Configuration Guide 53 1002253 01 Displaying OSPF information 25 ...
Страница 932: ...856 BigIron RX Series Configuration Guide 53 1002253 01 Generalized TTL security mechanism support 26 ...
Страница 980: ...904 BigIron RX Series Configuration Guide 53 1002253 01 Clearing IS IS information 28 ...
Страница 1000: ...924 BigIron RX Series Configuration Guide 53 1002253 01 Using secure copy 30 ...
Страница 1088: ...1012 BigIron RX Series Configuration Guide 53 1002253 01 IP source guard 35 ...
Страница 1108: ...1032 BigIron RX Series Configuration Guide 53 1002253 01 Reading CDP packets 37 ...
Страница 1126: ...1050 BigIron RX Series Configuration Guide 53 1002253 01 Clearing sFlow statistics 39 ...
Страница 1140: ...1064 BigIron RX Series Configuration Guide 53 1002253 01 802 1s Multiple Spanning Tree Protocol 40 ...
Страница 1324: ...1248 BigIron RX Series Configuration Guide 53 1002253 01 Displaying OSPFv3 information 48 ...
Страница 1363: ...BigIron RX Series Configuration Guide 1287 53 1002253 01 Continuous System Monitor 51 ...
Страница 1364: ...1288 BigIron RX Series Configuration Guide 53 1002253 01 Continuous System Monitor 51 ...
Страница 1404: ...1328 BigIron RX Series Configuration Guide 53 1002253 01 Commands That Require a Reload D ...
Страница 1458: ...1382 BigIron RX Series Configuration Guide 53 1002253 01 VSRP E ...