User Authentication
3-63
Configuring Port Security
Port security is a feature that allows you to configure a switch port with one or more
device MAC addresses that are authorized to access the network through that port.
When port security is enabled on a port, the switch stops learning new MAC
addresses on the specified port. Only incoming traffic with source addresses already
stored in the dynamic or static address table will be accepted as authorized to
access the network through that port. If a device with an unauthorized MAC address
attempts to use the switch port, the intrusion will be detected and the switch can
automatically take action by disabling the port and sending a trap message.
To use port security, first allow the switch to dynamically learn the
<source MAC address, VLAN> pair for frames received on a port for an initial
training period, and then enable port security to stop address learning. Be sure you
enable the learning function long enough to ensure that all valid VLAN members
have been registered on the selected port. Note that you can also restrict the
maximum number of addresses that can be learned by a port.
To add new VLAN members at a later time, you can manually add secure addresses
with the Static Address Table (page 3-108), or turn off port security to reenable the
learning function long enough for new VLAN members to be registered. Learning
may then be disabled again, if desired, for security.
Command Usage
• A secure port has the following restrictions:
• Cannot use port monitoring.
• Cannot be a multi-VLAN port.
• It cannot be used as a member of a static or dynamic trunk.
• It should not be connected to a network interconnection device.
• If a port is disabled (shut down) due to a security violation, it must be manually
re-enabled from the Port/Port Configuration page
(Chapter ).
Command Attributes
•
Port
– Port number.
• Name
– Descriptive text (page 4-112).
•
Action
– Indicates the action to be taken when a port security violation is detected:
•
None
: No action should be taken. (This is the default.)
•
Trap
: Send an SNMP trap message.
•
Shutdown
: Disable the port.
•
Trap and Shutdown
: Send an SNMP trap message and disable the port.
•
Security Status
– Enables or disables port security on the port. (Default: Disabled)
•
Max MAC Count
– The maximum number of MAC addresses that can be learned
on a port. (Range: 0 - 1024, where 0 means disabled)
•
Trunk
– Trunk number if port is a member (page 3-86 and 3-88).
Содержание 8124PL2
Страница 1: ...MANAGEMENT GUIDE TigerSwitchTM 10 100 1000 24 Port Managed Switch with PoE SMC8124PL2 ...
Страница 2: ......
Страница 20: ...xvi Contents ...
Страница 27: ...xxiii Figures ...
Страница 35: ...Introduction 1 8 1 ...
Страница 45: ...Initial Configuration 2 10 2 ...
Страница 148: ...Port Configuration 3 103 Figure 3 61 Displaying Etherlike and RMON Statistics ...
Страница 473: ...Command Line Interface 4 240 4 ...
Страница 477: ...Software Specifications A 4 A ...
Страница 489: ...Index Index 4 menu list 3 3 panel display 3 3 ...
Страница 490: ......