
Operation Manual – Port Security
H3C S5500-EI Series Ethernet Switches
Chapter 1 Port Security Configuration
1-6
To do…
Use the command…
Remarks
Set the maximum number
of secure MAC addresses
allowed on a port
port-security
max-mac-count
count-value
Required
Not limited by default
1.5 Setting the Port Security Mode
Before setting the port security mode, ensure that:
z
802.1x is disabled, the port access control method is macbased, and the port
access control mode is auto.
z
MAC authentication is disabled.
Otherwise, you will see an error message and your configuration will fail.
On the other hand, after setting the port security mode on a port, you cannot change
any of the above configurations.
Note:
z
With port security disabled, you can configure the port security mode but your
configuration does not take effect.
z
With port security enabled, you can change the port security mode of a port only
when the port is operating in noRestrictions mode, the default mode. You can use
the
undo port-security port-mode
command to restore the default port security
mode.
z
You cannot change the port security mode of a port when any user is present on the
port.
z
Configuration of port security mode and aggregation are mutually exclusive. You
cannot configure both of them on a port.
1.5.1 Enabling the autoLearn Mode
I. Configuration prerequisites
Before enabling the autoLearn mode, you need to set the maximum number of secure
MAC addresses allowed on the port.
II. Configuration procedure
Follow these steps to enable the autoLearn mode: