Configuring and Monitoring Port Security
MAC Lockdown
M i x e d U s e r s
Internal
Network
External
Network
Switch 1
Server A
Server A
is locked down
to Switch 1, Uplink 2
PROBLEM:
If this link fails,
traffic to Server A will not use
the backup path via Switch 3
Switch 2
Switch 3
Switch 4
Figure 9-10. Connectivity Problems Using MAC Lockdown with Multiple Paths
The resultant connectivity issues would prevent you from locking down
Server A to Switch 1. And when you remove the MAC Lockdown from Switch
1 (to prevent broadcast storms or other connectivity issues), you then open
the network to security problems. The use of MAC Lockdown as shown in the
above figure would defeat the purpose of using STP or having an alternate
path.
Technologies such as STP are primarily intended for an internal campus
network environment in which all users are trusted. STP does not work well
with MAC Lockdown.
If you deploy MAC Lockdown as shown in the Model Topology in figure 9-9
(page 9-22), you should have no problems with either security or connectivity.
9-24
Содержание ProCurve 2800 Series
Страница 2: ......
Страница 24: ...Getting Started To Set Up and Install the Switch in Your Network This page is intentionally unused 1 12 ...
Страница 44: ...Configuring Username and Password Security Front Panel Security This page is intentionally unused 2 20 ...
Страница 132: ...RADIUS Authentication and Accounting Messages Related to RADIUS Operation This page is intentionally unused 5 32 ...
Страница 182: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup This page is intentionally unused 7 22 ...
Страница 268: ...Configuring and Monitoring Port Security Operating Notes for Port Security This page is intentionally unused 9 38 ...
Страница 299: ......