
1-11
To do…
Use the command…
Remarks
interface-number
Ignore the authorization
information from the RADIUS
server
port-security authorization
ignore
Required
By default, a port uses the
authorization information from the
RADIUS server.
Displaying and Maintaining Port Security
To do…
Use the command…
Remarks
Display port security configuration
information, operation information,
and statistics about one or more
ports or all ports
display port-security
[
interface
interface-list
]
Available in any
view
Display information about secure
MAC addresses
display port-security mac-address security
[
interface interface-type interface-number
] [
vlan
vlan-id
] [
count
]
Available in any
view
Display information about blocked
MAC addresses
display port-security mac-address block
[
interface interface-type interface-number
] [
vlan
vlan-id
] [
count
]
Available in any
view
Port Security Configuration Examples
Configuring the autoLearn Mode
Network requirements
Restrict port GigabitEthernet 1/0/1
of the switch as follows:
z
Allow up to 64 users to access the port without authentication and permit the port to learn and add
the MAC addresses of the users as secure MAC addresses.
z
After the number of secure MAC addresses reaches 64, the port stops learning MAC addresses. If
any frame with an unknown MAC address arrives, intrusion protection is triggered and the port is
disabled and stays silence for 30 seconds.
Figure 1-1
Network diagram for configuring the autoLearn mode
Configuration procedure
1) Configure port security
# Enable port security.
<Switch> system-view
[Switch] port-security enable
# Enable intrusion protection trap.
[Switch] port-security trap intrusion
[Switch] interface gigabitethernet 1/0/1
# Set the maximum number of secure MAC addresses allowed on the port to 64.
Содержание S5120-EI Series
Страница 139: ...ii...
Страница 268: ...3 3 SwitchB system view SwitchB interface vlan interface 1 SwitchB Vlan interface1 ip address dhcp alloc...
Страница 328: ...i Table of Contents 1 Dual Stack Configuration 1 1 Dual Stack Overview 1 1 Configuring Dual Stack 1 1...
Страница 578: ...1 21 C...
Страница 739: ...1 12 Enable ARP detection based on 802 1X security entries SwitchB arp detection mode dot1x...
Страница 926: ...2 8...
Страница 942: ...ii Single Device Upgrade 3 4 IRF System Upgrade 3 5...
Страница 985: ...1 1...
Страница 1018: ...1 6...