8-7
Parameters
None
Description
Use the
port-security enable
command to enable port security.
Use the
undo port-security enable
command to disable port security.
By default, port security is disabled.
Note that:
1) Port security cannot be enabled when 802.1X or MAC authentication is enabled globally.
2) Enabling port security resets the following configurations on a port to the defaults bracketed,
making them dependent completely on the port security mode:
z
802.1X (disabled), port access control method (
macbased
), and port access control mode (
auto
)
z
MAC authentication (disabled)
3) Disabling port security resets the following configurations on a port to the defaults bracketed:
z
Port security mode (noRestrictions)
z
802.1X (disabled), port access control method (
macbased
), and port access control mode (
auto
)
z
MAC authentication (disabled)
4) Port security cannot be disabled if there is any user present on a port.
Related commands:
display port-security
,
dot1x
,
dot1x port-method
,
dot1x port-control
in
802.1X
Commands
of the
Security Volume
,
mac-authentication
in
MAC Authentication
Commands
of the
Security Volume
.
Examples
# Enable port security.
<Sysname> system-view
[Sysname] port-security enable
port-security intrusion-mode
Syntax
port-security intrusion-mode
{
blockmac
|
disableport
|
disableport-temporarily
}
undo port-security intrusion-mode
View
Layer 2 Ethernet interface view
Default Level
2: System level
Parameters
blockmac
: Adds the source MAC addresses of illegal frames to the blocked MAC address list and
discards frames with blocked source MAC addresses. A blocked MAC address is restored to normal
after being blocked for three minutes, which is fixed and cannot be changed. You can use the
display
port-security mac-address block
command to view the blocked MAC address list.
disableport
: Disables the port permanently upon detecting an illegal frame received on the port.
Содержание E4510-48G
Страница 109: ...2 18 Sysname interface bridge aggregation 1 Sysname Bridge Aggregation1 shutdown ...
Страница 309: ...6 4 Sysname interface vlan interface 1 Sysname Vlan interface1 ip address dhcp alloc ...
Страница 324: ...8 3 Sysname interface vlan interface 1 Sysname Vlan interface1 ip address bootp alloc ...
Страница 530: ...2 5 Sysname mvlan 100 subvlan 10 to 15 ...
Страница 739: ...8 15 Sysname system view Sysname port security trap addresslearned ...
Страница 819: ...13 11 Sysname system view Sysname public key peer key2 import sshkey key pub ...
Страница 857: ...iii 7 Track Configuration Commands 7 1 Track Configuration Commands 7 1 display track 7 1 track nqa 7 2 ...
Страница 914: ...5 17 Sysname reset oam ...
Страница 1064: ...5 30 Slot 2 Set next configuration file successfully ...
Страница 1325: ...21 13 Examples Redirect to member 2 Sysname irf switch to 2 Sysname Slave 2 ...