1-7
Configuring Procedure
Follow these steps to enable any other port security mode:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Set an OUI value for
user authentication
port-security
oui
oui-value index
index-value
Optional
Not configured by default.
The command is required for
the
userlogin-withoui
mode.
Enter interface view
interface
interface-type
interface-number
—
Set the port security
mode
port-security
port-mode
{
autolearn
|
mac-authentication |
mac-else-userlogin-secure |
mac-else-userlogin-secure-ext |
secure | userlogin | userlogin-secure
| userlogin-secure-ext |
userlogin-secure-or-mac |
userlogin-secure-or-mac-ext |
userlogin-withoui
}
Required
By default, a port operates in
noRestrictions mode.
z
You cannot change the maximum number of secure MAC addresses allowed on a port that
operates in autoLearn mode.
z
OUI, defined by IEEE, is the first 24 bits of the MAC address and uniquely identifies a device
vendor.
z
You can configure multiple OUI values. However, a port in userLoginWithOUI mode allows only
one 802.1X user and one user whose MAC address contains a specified OUI.
z
After enabling port security, you can change the port security mode of a port only when the port is
operating in noRestrictions mode, the default mode. To change the port security mode of a port
operating in any other mode, use the
undo port-security port-mode
command to restore the
default port security mode at first.
z
You cannot change the port security mode of a port with users online.
Configuring Port Security Features
Configuring NTK
The need to know (NTK) feature checks the destination MAC addresses in outbound frames to allow
frames to be forwarded to only devices passing authentication. The NTK feature supports three modes:
z
ntkonly
: Forwards only frames destined for authenticated MAC addresses.
z
ntk-withbroadcasts
: Forwards only frames destined for authenticated MAC addresses or the
broadcast address.
z
ntk-withmulticasts
: Forwards only frames destined for authenticated MAC addresses, multicast
addresses, or the broadcast address.
Содержание 4500G PWR 24-Port
Страница 200: ...1 5 ProviderB GigabitEthernet1 0 2 undo stp enable ProviderB GigabitEthernet1 0 2 bpdu tunnel dot1q stp ...
Страница 252: ...1 7 Clearing ARP entries from the ARP table may cause communication failures ...
Страница 362: ...i Table of Contents 1 Dual Stack Configuration 1 1 Dual Stack Overview 1 1 Configuring Dual Stack 1 1 ...
Страница 407: ...1 8 1 1 ms 1 ms 1 ms 1 1 6 1 2 1 ms 1 ms 1 ms 1 1 4 1 3 1 ms 1 ms 1 ms 1 1 2 2 Trace complete ...
Страница 786: ...1 16 3 In the case of PIM SM use the display current configuration command to check the BSR and RP information ...
Страница 1387: ...1 23 ...
Страница 1443: ...i Table of Contents 1 URPF Configuration 1 1 URPF Overview 1 1 What is URPF 1 1 How URPF Works 1 1 Configuring URPF 1 2 ...
Страница 1720: ...ii Single Device Upgrade 3 4 IRF System Upgrade 3 5 ...