196
# Set the secure MAC aging timer to 30 minutes.
[Device] port-security timer autolearn aging 30
# Set port security's limit on the number of secure MAC addresses to 64 on port FortyGigE 1/1/1.
[Device] interface fortygige 1/1/1
[Device-FortyGigE1/1/1] port-security max-mac-count 64
# Set the port security mode to autoLearn.
[Device-FortyGigE1/1/1] port-security port-mode autolearn
# Configure the port to be silent for 30 seconds after the intrusion protection feature is triggered.
[Device-FortyGigE1/1/1] port-security intrusion-mode disableport-temporarily
[Device-FortyGigE1/1/1] quit
[Device] port-security timer disableport 30
Verifying the configuration
# Verify the port security configuration.
[Device] display port-security interface fortygige 1/1/1
Port security parameters:
Port security : Enabled
AutoLearn aging time : 30 min
Disableport timeout : 30 s
MAC move : Denied
Authorization fail : Online
NAS-ID profile is not configured
OUI value list :
FortyGigE1/1/1 is link-up
Port mode : autoLearn
NeedToKnow mode : Disabled
Intrusion protection mode : DisablePortTemporarily
Security MAC address attribute
Learning mode : Sticky
Aging type : Periodical
Max secure MAC addresses : 64
Current secure MAC addresses : 5
Authorization : Permitted
NAS-ID profile is not configured
The output shows the following information:
•
The port security's limit on the number of secure MAC addresses on the port is 64.
•
The port security mode is autoLearn.
•
The intrusion protection action is disabling the port (DisablePortTemporarily) for 30 seconds.
The port allows for MAC address learning, and you can display the number of learned MAC
addresses in the
Current secure MAC addresses
field.
# Display additional information about the learned MAC addresses.
[Device] interface fortygige 1/1/1
[Device-FortyGigE1/1/1] display this
#
interface FortyGigE1/1/1
port-security max-mac-count 64