Layer 2 Switching Commands
298
Statically locked MAC addresses are not eligible for aging. If a packet arrives
on a port with a source MAC address that is statically locked on another port,
then the packet is discarded.
To configure static locking only, set the dynamic MAC limit to 0 and
configure the static MAC addresses on the interface. To configure dynamic
locking only, set the static MAC limit to 0, and set the appropriate dynamic
MAC address limit.
MAC addresses seen on an interface other than the learned or configured
MAC addresses and in excess of the limit are considered violations of port
security. Trap issuance violation actions can be configured using the
snmp-
server enable traps
port-security
command. The default action is to log a
message and send an SNMP trap. Port security can optionally error disable an
interface on which a violation occurs using the
switchport port-security
violation shutdown
command.
Enabling mode configuration converts all the existing dynamically learned
MAC addresses on an interface to sticky. It also converts the last violation
MAC address to sticky, even if the dynamic limit is set to 0. These MAC
addresses will not age out and will appear in the running-config. In addition,
new addresses learned on the interface will also become sticky. Note that
sticky is not the same as static – the difference is that all sticky addresses for
an interface are removed from the running-config when the interface is taken
out of sticky mode. Static addresses must be removed from the running-
config individually.
Sticky MAC addresses appear in the running-config in the following form:
switchport port-security mac-address sticky 0011.2233.4455 vlan 33
Statically locked MAC addresses appear in the running-config in the
following form:
switchport port-security mac-address 0011.2233.4455 vlan 33
In order for sticky or static MAC addresses to survive a reboot, the
configuration must be saved.
Port security must be enabled globally and on the interface in order to be
active.
Port security should only be enabled on access mode ports and not on trunk
mode ports. This recommendation is not enforced by the switch.
Содержание N1100-ON
Страница 2: ......
Страница 4: ......
Страница 258: ...Using the CLI 258 ...
Страница 488: ...Layer 2 Switching Commands 488 Operational State Querier Operational version 1 ...
Страница 656: ...Layer 2 Switching Commands 656 10 ...
Страница 1128: ...Audio Visual Bridging Commands 1128 ...
Страница 1186: ...Data Center Technology Commands 1186 ...
Страница 1414: ...Layer 3 Routing Commands 1414 Command History Introduced in version 6 2 0 1 firmware Example console route map set metric 6432 ...
Страница 1435: ...Layer 3 Routing Commands 1435 Number of Joins 7 Number of Groups 1 ...
Страница 1598: ...Layer 3 Routing Commands 1598 Vl10 Rx 0 0 0 0 0 0 0 Tx 2 0 0 0 0 0 0 Invalid Packets Received 0 ...
Страница 1621: ...Layer 3 Routing Commands 1621 Vl10 Rx 0 0 0 0 0 0 0 Tx 2 0 0 0 0 0 0 Invalid Packets Received 0 ...
Страница 2330: ......
Страница 2331: ...www dell com support dell com Printed in the U S A ...
Страница 2332: ......