mac-address static 0003-0003-0003 Ethernet2/0/1 vlan 2
mac-address static 0004-0004-0004 Ethernet2/0/2 vlan 2
#
return
6.9.2 Example for Configuring Port Security
Networking Requirements
As shown in
, a company wants to prevent non-employees from accessing the intranet.
To achieve this information security goal, the company needs to enable the sticky MAC function
on the Huawei interface connected to computers of employees and set the maximum number of
MAC addresses learned on the interface to the total number of trusted computers.
Figure 6-2
Network diagram of port security configuration
Router
Switch
Internet
PC1
PC2
PC3
VLAN 10
Eth2/0/1
Configuration Roadmap
The configuration roadmap is as follows:
1.
Create a VLAN and set the link type of the interface to trunk.
2.
Enable the port security function.
3.
Enable the sticky MAC function on the interface.
4.
Configure the protective action on the interface.
5.
Set the maximum number of MAC addresses that can be learned on the interface.
Data Preparation
To complete the configuration, you need the following data:
Huawei AR3200 Series Enterprise Routers
Configuration Guide - LAN
6 MAC Address Table Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
175