Configuring and Monitoring Port Security
Port Security
Syntax:
port-security
(Continued)
clear-intrusion-flag
Clears the intrusion flag for a specific port. (See “Reading
Intrusion Alerts and Resetting Alert Flags” on page
no port-security
<port-list>
mac-address <
mac-addr
> [
<mac-addr>
<mac-addr>
]
Removes the specified learned MAC address(es) from the
specified port.
Retention of Static Addresses
Static MAC addresses do not age-out. MAC addresses learned by using
learn-
mode continuous
or
learn-mode limited-continuous
age out according to the
currently configured MAC age time. (For information on the
mac-age-time
command, refer to the chapter titled “Interface Access and System Informa
tion” in the
Management and Configuration Guide
for your switch.
Learned Addresses.
In the following two cases, a port in Static learn mode
retains a learned MAC address even if you later reboot the switch or disable
port security for that port:
■
The port learns a MAC address after you configure the port for Static learn
mode in both the startup-config file and the running-config file (by exe
cuting the
write memory
command).
■
The port learns a MAC address after you configure the port for Static learn
mode in only the running-config file and, after the address is learned, you
execute
write memory
to configure the startup-config file to match the
running-config file.
To remove an address learned using either of the preceding methods, do one
of the following:
■
Delete the address by using
no port-security <
port-number
> mac-address
<
mac-addr
>
.
■
Download a configuration file that does not include the unwanted MAC
address assignment.
■
Reset the switch to its factory-default configuration.
Assigned/Authorized Addresses.
: If you manually assign a MAC address
(using
port-security <
port-number
> address-list <
mac-addr
>
) and then execute
write memory
, the assigned MAC address remains in memory until you do one
of the following:
13-17
Содержание PROCURVE 2910AL
Страница 1: ...Access Security Guide ProCurve Switches W 14 03 2910al www procurve com ...
Страница 2: ......
Страница 3: ...HP ProCurve 2910al Switch February 2009 W 14 03 Access Security Guide ...
Страница 84: ...Configuring Username and Password Security Front Panel Security 2 36 ...
Страница 156: ...TACACS Authentication Operating Notes 4 30 ...
Страница 288: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup 8 22 ...
Страница 416: ...Configuring Advanced Threat Protection Using the Instrumentation Monitor 10 28 ...
Страница 516: ...Configuring Port Based and User Based Access Control 802 1X Messages Related to 802 1X Operation 12 76 ...
Страница 527: ...Configuring and Monitoring Port Security Port Security Figure 13 4 Examples of Show Mac Address Outputs 13 11 ...
Страница 572: ...Using Authorized IP Managers Operating Notes 14 14 ...
Страница 592: ...12 Index ...
Страница 593: ......
Страница 594: ... Copyright 2009 Hewlett Packard Development Company L P February 2009 Manual Part Number 5992 5439 ...