112
The port security’s limit on the number of MAC addresses on a port is independent of the MAC learning
limit described in MAC address table configuration
in
Layer 2—LAN Switching Configuration Guide
.
Setting the port security mode
Configuration prerequisites
Before you set a port security mode for a port, complete the following tasks:
1.
Disable 802.1X and MAC authentication.
2.
Check that the port does not belong to any aggregation group or service loopback group.
3.
If you are configuring the autoLearn mode, set port security’s limit on the number of MAC
addresses. You cannot change the setting when the port is operating in autoLearn mode.
You can specify a port security mode when port security is disabled, but your configuration cannot take
effect.
You cannot change the port security mode of a port when online users are present.
Configuration procedure
To enable a port security mode:
To do…
Use the command…
Remarks
1.
Enter system view.
system-view
—
2.
Set an OUI value for
user authentication.
port-security
oui
oui-value
index
index-value
Optional.
Not configured by default.
The command is required for the
userlogin-withoui
mode.
3.
Enter Layer 2 Ethernet
interface view.
interface
interface-type interface-
number
—
4.
Set the port security
mode.
port-security
port-mode
{
autolearn
|
mac-authentication
|
mac-else-
userlogin-secure
|
mac-else-
userlogin-secure-ext
|
secure
|
userlogin
|
userlogin-secure
|
userlogin-secure-ext
|
userlogin-
secure-or-mac
|
userlogin-secure-or-
mac-ext
|
userlogin-withoui
}
Required.
By default, a port operates in
noRestrictions mode.
An OUI, as defined by the IEEE, is the first 24 bits of the MAC address, which uniquely identifies a
device vendor.
A port in userLoginWithOUI mode allows only one 802.1X user and one user whose MAC address
contains any specified OUI to pass authentication concurrently.
Содержание A5830 Series
Страница 207: ...199 Figure 62 SFTP client interface ...