
200
When the maximum number of secure MAC address entries is reached, the port changes to secure
mode. In secure mode, the port cannot add or learn any more secure MAC addresses. The port
allows only frames sourced from secure MAC addresses or MAC addresses configured by using the
mac-address dynamic
or
mac-address static
command to pass through.
Configuration prerequisites
Before you configure secure MAC addresses, complete the following tasks:
•
Enable port security.
•
Set port security's limit on the number of MAC addresses on the port. Perform this task before
you enable autoLearn mode.
•
Set the port security mode to autoLearn.
•
Configure the port to permit packets of the specified VLAN to pass or add the port to the VLAN.
Make sure the VLAN already exists.
Configuration procedure
To configure a secure MAC address:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
(Optional.) Set the
secure MAC aging
timer.
port-security timer autolearn aging
time-value
By default, secure MAC
addresses do not age out.
3.
Configure a secure
MAC address.
•
In system view:
port-security
mac-address
security
[
sticky
]
mac-address
interface
interface-type
interface-number
vlan
vlan-id
•
In Layer 2 Ethernet interface view:
a. interface
interface-type
interface-number
b. port-security mac-address
security
[
sticky
]
mac-address
vlan
vlan-id
c. quit
By default, no secure MAC
address exists.
In the same VLAN, a MAC
address cannot be specified as
both a static secure MAC address
and a sticky MAC address.
4.
Enter Layer 2 Ethernet
interface view.
interface
interface-type
interface-number
N/A
5.
(Optional.) Enable
inactivity aging.
port-security mac-address
aging-type inactivity
By default, the inactivity aging
feature is disabled.
6.
(Optional.) Enable the
dynamic secure MAC
feature.
port-security mac-address dynamic
By default, this feature is
disabled. Sticky MAC addresses
can be saved to the configuration
file. Once saved, they can survive
a device reboot.
Ignoring authorization information from the server
You can configure a port to ignore the authorization information received from the server (local or
remote) after an 802.1X or MAC authentication user passes authentication.
Содержание 10500 series
Страница 326: ...312 No duration limit for this SA ...