14-33
Configuring and Monitoring Port Security
Port Security and MAC Lockout
If someone using a locked out MAC address tries to send data through the
switch a message similar to the following is generated in the log file:
Lockout logging format:
W 10/30/03 21:35:15 maclock: module A: 0001e6-1f96c0
detected on port A15
W 10/30/03 21:35:18 maclock: module A: 0001e6-1f96c0
detected on port A15
W 10/30/03 21:35:18 maclock: module A: Ceasing lock-out
logs for 5m
As with MAC Lockdown a rate limiting algorithm is used on the log file so that
it does not become overclogged with error messages. (Refer to “Limiting the
Frequency of Log Messages” on page 14-26.)
Port Security and MAC Lockout
MAC Lockout is independent of port-security and in fact will override it. MAC
Lockout is preferable to port-security to stop access from known devices
because it can be configured for all ports on the switch with one command.
It is possible to use MAC Lockout in conjunction with port-security. You can
use MAC Lockout to lock out a single address—deny access to a specific
device—but still allow the switch some flexibility in learning other MAC
Addresses. Be careful if you use both together, however:
•
If a MAC Address is locked out and appears in a static learn table in
port-security, the apparently “authorized” address will still be locked
out anyway.
•
MAC entry configurations set by port security will be kept even if MAC
Lockout is configured and the original port security settings will be
honored once the Lockout is removed.
•
A port security static address is permitted to be a lockout address. In
that case (MAC Lockout), the address will be locked out (SA/DA drop)
even though it’s an “authorized” address from the perspective of port
security.
•
When MAC Lockout entries are deleted, port security will then re-
learn the address as needed later on.
Содержание E3800 Series
Страница 1: ...HP Switch Software E3800 switches Software version KA 15 03 September 2011 Access Security Guide ...
Страница 2: ......
Страница 3: ...HP Networking E3800 Switches Access Security Guide September 2011 KA 15 03 ...
Страница 30: ...xxviii ...
Страница 86: ...2 36 Configuring Username and Password Security Password Recovery ...
Страница 186: ...4 72 Web and MAC Authentication Client Status ...
Страница 290: ...6 74 RADIUS Authentication Authorization and Accounting Dynamic Removal of Authentication Limits ...
Страница 364: ...8 32 Configuring Secure Shell SSH Messages Related to SSH Operation ...
Страница 510: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Страница 548: ...11 38 Configuring Advanced Threat Protection Using the Instrumentation Monitor ...
Страница 572: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Страница 659: ...14 11 Configuring and Monitoring Port Security Port Security Figure 14 5 Examples of Show Mac Address Outputs ...
Страница 730: ...20 Index ...
Страница 731: ......