I
NTERFACE
C
OMMANDS
3-101
port security
Use this command to enable and configure port security on a port.
Use the
no
form to disable port security or reset the intrusion
action to the default.
Syntax
port security
[
action trap-and-shutdown
]
no port security
[
action
]
action
- Indicates the security action to be taken when a
port security violation is detected (applies globally to all
ports).
trap-and-shutdown
- Issue an SNMP trap message and
disable the port.
Default Setting
Status: Disabled
Action: None
Command Mode
Interface Configuration (Ethernet)
Command Usage
• If you enable port security, the switch will stop dynamically
learning new addresses on the specified port. Only incoming
traffic with source addresses already stored in the dynamic or
static address table will be accepted.
• To use port security, first allow the switch to dynamically learn
the <source MAC address, VLAN> pair for frames received on a
port for an initial training period, and then enable port security
to stop address learning. Be sure you enable the learning
function long enough to ensure that all valid VLAN members
have been registered on the selected port.
• To add new VLAN members at a later time, you can manually
add secure addresses with the
mac-address-table static
command, or turn off port security to reenable the learning
function long enough for new VLAN members to be registered.
Learning may then be disabled again, if desired, for security.
b_mgmt.book Page 101 Tuesday, July 8, 2003 5:24 PM
Содержание 8612T - annexe 1
Страница 2: ......
Страница 32: ...SWITCH MANAGEMENT 1 18 ...
Страница 167: ...801 1X PORT AUTHENTICATION 2 135 ...
Страница 168: ...CONFIGURING THE SWITCH 2 136 ...
Страница 362: ...GLOSSARY Glossary 8 ...
Страница 365: ......