Configuring the Action on Intrusion
When an unauthorized MAC address inserts at a port, the 8239 can be configured
with any of the following actions:
¹
disable and trap to disable the port and send a trap
¹
disable only to disable the port
¹
trap only to send a trap
¹
no action to take no action
The default value for the action on intrusion is TRAP_ONLY. To change the action
on intrusion, use the SET SECURITY_PORT ACTION_ON_INTRUSION terminal
interface command.
When the port is disabled due to a security intrusion:
¹
A DISPLAY PORT command results in listing the port status as SECURITY
BREACH
¹
The port’s green status LED is off
¹
The port’s yellow status LED is blinking
Once a port has been disabled due to a security intrusion, the port must be
re-enabled before it can be inserted into the stack data ring again. The command to
re-enable the port is ENABLE PORT.
When the 8239 is configured to send a trap on a security intrusion, the trap can be
displayed on the terminal interface or it can be sent to an SNMP manager if a valid
entry is in the trap community table for IBM 8239 traps. Refer to “Trap Processing”
on page 7-10 for more information.
To display what security intrusions have occurred, use the DISPLAY SECURITY
INTRUDER_LIST terminal interface command. The 20 most recent intrusions for
the entire stack are displayed.
To clear all of the entries in the security intruder list, use the CLEAR SECURITY
INTRUDER_LIST terminal interface command.
Enabling Port Security
In order for the 8239 to perform port security, port security must be enabled for
each port desired. The default setting disables port security. To enable port
security, use the ENABLE SECURITY_PORT terminal interface command.
Note: Port security should be enabled
after the authorized MAC addresses are
configured for the port so that premature actions on intrusions can be
avoided.
Ring In/Ring Out Concepts (8239 Model 1 only)
The 8239 Model 1 contains a Ring-In/Ring-Out (RI/RO) slot that can be used to
insert either an RJ-45 RI/RO Module or an Optical Fiber RI/RO Module. The 8239
RI/RO Module allows the 8239 stack to be connected to another 8239 stack or to
other compatible hubs or concentrators. The RI/RO Module allows expansion of the
network to include multiple devices that are a part of the same physical network.
6-8
8239 Setup and User’s Guide
Содержание 8239 Token-Ring Stackable Hub
Страница 1: ...8239 Token Ring Stackable Hub Setup and User s Guide GA27 4209 00...
Страница 2: ......
Страница 3: ...8239 Token Ring Stackable Hub Setup and User s Guide GA27 4209 00...
Страница 8: ...vi 8239 Setup and User s Guide...
Страница 10: ...viii 8239 Setup and User s Guide...
Страница 28: ...1 8 8239 Setup and User s Guide...
Страница 36: ...2 8 8239 Setup and User s Guide...
Страница 70: ...5 18 8239 Setup and User s Guide...
Страница 102: ...7 18 8239 Setup and User s Guide...
Страница 120: ...8 18 8239 Setup and User s Guide...
Страница 135: ......
Страница 139: ......
Страница 140: ...Printed in USA GA27 4209 00...
Страница 141: ...Spine information 8239 Token Ring Stackable Hub Setup and User s Guide...