21. Port Security
ROX™ v2.2 User Guide
204
RuggedBackbone™ RX5000
Figure 21.5. Port Security menu
21.2.1. Port Security Parameters
Figure 21.6. Port Security form
Security Mode
Synopsis: string - one of the following keywords { dot1x_mac_auth, dot1x, per_macaddress, off }
Default: off
Enables or disables the security feature for the port. The following port access control types are
available:
• Static MAC address based. With this method, authorized MAC address(es) should be configured
in the static MAC address table. If some MAC addresses are not known in advance (or which
port they are going to reside behind is unknown), there is still an option to configure the switch
to auto-learn a certain number of MAC addresses. Once learned, they don't age out until the unit
is reset or the link goes down.
• IEEE 802.1X standard authentication.
• IEEE 802.1X with MAC Authentication, also known as MAC-Authentication Bypass. With this
method, the device can authenticate clients based on the client's MAC address, if IEEE 802.1X
authentication times out.
Auto Learn
Synopsis: integer
Default:
The maximum number of MAC addresses that can be dynamically learned on the port. If there are
static addresses configured on the port, the actual number of addresses allowed to be learned is
this number minus the number of the static MAC addresses.
Shutdown Time
Synopsis: integer
How long to shut down an interface if a security violation occurs.