321
Usage guidelines
This command enables the device to periodically detect traffic data from secure MAC addresses.
If only the aging timer is configured, the aging timer counts up regardless of whether traffic data has
been sent from the secure MAC addresses. When you use the aging timer together with the inactivity
aging feature, the aging timer restarts once traffic data is detected from the secure MAC addresses.
The secure MAC addresses age out only when no traffic data is detected within the aging timer.
The inactivity aging feature prevents the unauthorized use of a secure MAC address when the
authorized user is offline. The feature also removes outdated secure MAC addresses so that new
secure MAC addresses can be learned or configured.
If the aging timer is set to a value not less than 60 seconds, the traffic data detection interval is fixed
at 30 seconds.
If the aging timer is set to a value less than 60 seconds, the traffic data detection interval is the
effective aging period.
To set the aging timer for secure MAC addresses, use the
port-security timer autolearn aging
command.
This command takes effect only on sticky MAC addresses and dynamic secure MAC addresses.
Examples
# Enable inactivity aging for secure MAC addresses on Ten-GigabitEthernet 1/0/1.
<Sysname> system-view
[Sysname] interface ten-gigabitethernet 1/0/1
[Sysname-Ten-GigabitEthernet1/0/1] port-security mac-address aging-type inactivity
Related commands
display port-security
port-security mac-address dynamic
Use
port-security mac-address dynamic
to enable the dynamic secure MAC feature.
Use
undo port-security mac-address dynamic
to disable the dynamic secure MAC feature.
Syntax
port-security mac-address dynamic
undo port-security mac-address dynamic
Default
The dynamic secure MAC feature is disabled. Sticky MAC addresses can be saved to the
configuration file. Once saved, they survive a device reboot.
Views
Layer 2 Ethernet interface view
Predefined user roles
network-admin
mdc-admin
Usage guidelines
The dynamic secure MAC feature converts sticky MAC addresses to dynamic and disables saving
them to the configuration file.
After you execute this command, you cannot manually configure sticky MAC addresses, and secure
MAC addresses learned by a port in autoLearn mode are dynamic. All dynamic MAC addresses are
Содержание FlexNetwork 7500 Series
Страница 350: ...335 Related commands display port security port security enable ...
Страница 379: ...364 Sysname system view Sysname keychain abc mode absolute Sysname keychain abc tcp kind 252 ...
Страница 519: ...504 Related commands display ssh2 algorithm ssh2 algorithm cipher ssh2 algorithm key exchange ssh2 algorithm mac ...