170
Default level
2: System level
Parameters
blockmac
: Adds the source MAC addresses of illegal frames to the blocked MAC address list and
discards frames with blocked source MAC addresses. This implements illegal traffic filtering on the port.
A blocked MAC address is restored to normal after being blocked for three minutes, which is fixed and
cannot be changed. To view the blocked MAC address list, use the
display port-security mac-address
block
command.
disableport
: Disables the port permanently upon detecting an illegal frame received on the port.
disableport-temporarily
: Disables the port for a specified period of time whenever it receives an illegal
frame. Use the
port-security timer disableport
command to set the period.
Description
Use the
port-security intrusion-mode
command to configure the intrusion protection feature so that the
port takes the pre-defined actions when intrusion protection is triggered on the port.
Use the
undo port-security intrusion-mode
command to restore the default.
By default, intrusion protection is disabled.
To restore the connection of the port, use the
undo shutdown
command.
Related commands:
display port-security
,
display port-security mac-address block
, and
port-security
timer disableport
.
Examples
# Configure port GigabitEthernet 1/0/1 to block the source MAC addresses of illegal frames after
intrusion protection is triggered.
<Sysname> system-view
[Sysname] interface gigabitethernet 1/0/1
[Sysname-GigabitEthernet1/0/1] port-security intrusion-mode blockmac
port-security mac-address security
Syntax
In Layer 2 Ethernet interface view:
port-security mac-address security
mac-address
vlan
vlan-id
In system view:
port-security
mac-address
security
mac-address
interface
interface-type interface-number
vlan
vlan-id
undo port-security mac-address security
[ [
mac-address
[
interface
interface-type interface-number
] ]
vlan
vlan-id
]
View
Layer 2 Ethernet Interface view, system view
Default level
2: System level
Parameters
mac-address
: Secure MAC address, in the H-H-H format.