169
port-security enable
Syntax
port-security enable
undo port-security enable
View
System view
Default level
2: System level
Parameters
None
Description
Use the
port-security enable
command to enable port security.
Use the
undo port-security enable
command to disable port security.
By default, port security is disabled.
1.
Port security cannot be enabled when 802.1X or MAC authentication is enabled globally.
2.
Enabling port security resets the following configurations on a port to the defaults bracketed,
making them dependent completely on the port security mode:
•
802.1X (
disabled
), port access control method (
macbased
), and port authorization mode (
auto
)
•
MAC authentication (
disabled
)
3.
Disabling port security resets the following configurations on a port to the defaults bracketed:
•
Port security mode (
noRestrictions
)
•
802.1X (
disabled
), port access control method (
macbased
), and port authorization mode (
auto
)
•
MAC authentication (
disabled
)
4.
Port security cannot be disabled when a user is present on a port.
Related commands:
display port-security
,
dot1x
,
dot1x port-method
, and
dot1x port-control
;
mac-authentication
.
Examples
# Enable port security.
<Sysname> system-view
[Sysname] port-security enable
port-security intrusion-mode
Syntax
port-security intrusion-mode
{
blockmac
|
disableport
|
disableport-temporarily
}
undo port-security intrusion-mode
View
Layer 2 Ethernet interface view