222
Step Command
Remarks
•
In interface view:
a. interface
interface-type
interface-number
b. port-security
nas-id-profile
profile-name
Enabling SNMP notifications for port security
Use this feature to report critical port security events to an NMS. For port security event notifications
to be sent correctly, you must also configure SNMP on the device. For more information about SNMP
configuration, see the network management and monitoring configuration guide for the device.
This feature takes effect only when the intrusion protection feature is configured by using the
port-security intrusion-mode
command.
To enable SNMP notifications for port security:
Step Command
Remarks
1.
Enter system
view.
system-view
N/A
2.
Enable SNMP
notifications for
port security.
snmp-agent trap enable port-security
[
address-learned
|
dot1x-failure
|
dot1x-logoff
|
dot1x-logon
|
intrusion
|
mac-auth-failure
|
mac-auth-logoff
|
mac-auth-logon
] *
By default, SNMP
notifications are disabled
for port security.
Displaying and maintaining port security
Execute
display
commands in any view:
Task Command
Display the port security configuration,
operation information, and statistics.
display port-security
[
interface interface-type
interface-number
]
Display information about secure MAC
addresses.
display port-security mac-address security
[
interface
interface-type interface-number
] [
vlan vlan-id
] [
count
]
Display information about blocked MAC
addresses.
display port-security mac-address block
[
interface
interface-type interface-number
] [
vlan vlan-id
] [
count
]
Port security configuration examples
autoLearn configuration example
Network requirements
As shown in
, configure Ten-GigabitEthernet 1/0/1 on the device to meet the following
requirements:
•
Accept up to 64 users without authentication.
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...