195
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable the
authorization-fail-offline
feature.
port-security authorization-fail
offline
By default, this feature is disabled,
and the device does not log off
users who fail ACL or user profile
authorization.
Displaying and maintaining port security
Execute
display
commands in any view:
Task Command
Display the port security configuration,
operation information, and statistics.
display port-security
[
interface interface-type
interface-number
]
Display information about secure MAC
addresses.
display port-security mac-address security
[
interface
interface-type interface-number
] [
vlan vlan-id
] [
count
]
Display information about blocked MAC
addresses.
display port-security mac-address block
[
interface
interface-type interface-number
] [
vlan vlan-id
] [
count
]
Port security configuration examples
autoLearn configuration example
Network requirements
As shown in
, configure port FortyGigE 1/1/1 on the device to meet the following
requirements:
•
Accept up to 64 users without authentication.
•
Be permitted to learn and add MAC addresses as sticky MAC addresses, and set the secure
MAC aging timer to 30 minutes.
•
Stop learning MAC addresses after the number of secure MAC addresses reaches 64. If any
frame with an unknown MAC address arrives, intrusion protection starts, and the port shuts
down and stays silent for 30 seconds.
Figure 71 Network diagram
Configuration procedure
# Enable port security.
<Device> system-view
[Device] port-security enable