C
OMMAND
L
INE
I
NTERFACE
3-94
Command Usage
• If you enable port security, the switch will stop dynamically learning
new addresses on the specified port. Only incoming traffic with source
addresses already stored in the dynamic or static address table will be
accepted.
• To use port security, first allow the switch to dynamically learn the
<source MAC address, VLAN> pair for frames received on a port for
an initial training period, and then enable port security to stop address
learning. Be sure you enable the learning function long enough to
ensure that all valid VLAN members have been registered on the
selected port.
• To add new VLAN members at a later time, you can manually add
secure addresses with the
mac-address-table static
command, or turn
off port security to reenable the learning function long enough for new
VLAN members to be registered. Learning may then be disabled again,
if desired, for security.
• A secure port has the following restrictions:
- Cannot be connected to a network interconnection device.
- Cannot be a member of a static trunk.
• If a port is disabled due to a security violation, it must be manually
re-enabled by using the
no shutdown
command.
• Although the
port security action
command is an Interface
Configuration command, it applies globally to all switch ports.
Example
This example sets the port security action for the switch and enables
port security for port 5.
clear counters
Use this command to clear statistics on an interface.
Console(config)#interface ethernet 1/5
Console(config-if)#port security action trap-and-shutdown
Console(config-if)#port security
Console(config-if)#
Содержание TigerSwitch 100
Страница 2: ......
Страница 30: ...SWITCH MANAGEMENT 1 16...
Страница 314: ...COMMAND LINE INTERFACE 3 170...
Страница 316: ...TROUBLESHOOTING A 2...
Страница 330: ...GLOSSARY Glossary 8...
Страница 333: ......