260
SIGNAMAX LLC • www.signamax.eu
Port Security Configuration
Overview
The port security is often applied in the access layer. It can limit the hosts which use switch
ports, permit some given hosts to access the network while others cannot.
The port security function binds the four elements (the MAC address, the IP address, the VLAN
ID and the PORT number) of a user flexibly to forbid the illegal users to access the network;
thereby to guarantee the security of the network data and ensure that the legal users obtain
adequate bandwidth.
Users can limit the hosts which can access the network via three kinds of rules. They are the
MAC rule, the IP rule and the MAX rule. The MAC rule has three binding modes: the MAC
binding, the MAC+IP binding and the MAC+VID binding; the IP rule can aim at one IP or a
series of IPs; the MAX rule can be used to limit the number of the maximum MAC addresses
that “learned freely” by a port (in order), and this number doesn’t include the legal MAC
addresses generated by the MAC rule and the IP rule.
Configurations of the three rules are:
(1) MAC Rule
MAC Binding:
(config-port-0/6)#port-security permit mac-address 0050.bac3.bebd
(config-port-0/6)#port-security deny mac-address 0050.bac3.bebd
MAC+VID Binding:
(config-port-0/6)#port-security permit mac-address 0050.bac3.bebd vlan-id 100
(config-port-0/6)#port-security deny mac-address 0050.bac3.bebd vlan-id 100
MAC+IP Binding:
(config-port-0/6)#port-security permit mac-address 0050.bac3.bebd ip-address 128.255.1.1
(config-port-0/6)#port-security deny mac-address 0050.bac3.bebd ip-address 128.255.1.1
(2) IP Rule
Содержание 065-7434
Страница 1: ...24 Port 10 100 L3 Switch Model 065 7434 Configuration Guide Revision A1 ...
Страница 245: ...245 SIGNAMAX LLC www signamax eu Application Example Example of configuring DHCP Snooping ...
Страница 302: ...302 SIGNAMAX LLC www signamax eu Default status no switching interface ...
Страница 368: ......
Страница 655: ...287 SIGNAMAX LLC www signamax eu Sub VLAN members in the system ...