Chapter 24: General Security Measures
Port Security
– 819 –
snooping is enabled and mac-learning is disabled, then only incoming
traffic with source addresses stored in the static address table will be
accepted, all other packets are dropped. Note that the dynamic
addresses stored in the address table when MAC address learning is
disabled are flushed from the system, and no dynamic addresses are
subsequently learned until MAC address learning has been re-enabled.
•
The mac-learning commands cannot be used if 802.1X Port
Authentication has been globally enabled on the switch with the
command, or if MAC Address Security has been
enabled by the
command on the same interface.
E
XAMPLE
The following example disables MAC address learning for port 2.
Console(config)#interface ethernet 1/2
Console(config-if)#no mac-learning
Console(config-if)#
R
ELATED
C
OMMANDS
port security
This command enables or configures port security. Use the
no
form without
any keywords to disable port security. Use the
no
form with the
appropriate keyword to restore the default settings for a response to a
security violation or for the maximum number of allowed addresses.
S
YNTAX
port security
[[
action
{
shutdown
|
trap
|
trap-and-shutdown
}] |
[
max-mac-count address-count
]]
no port security
[
action
|
max-mac-count
]
action
- Response to take when port security is violated.
shutdown
- Disable port only.
trap
- Issue SNMP trap message only.
trap-and-shutdown
- Issue SNMP trap message and disable
port.
max-mac-count
address-count
- The maximum number of MAC addresses that
can be learned on a port. (Range: 0 - 1024, where 0 means
disabled)
D
EFAULT
S
ETTING
Status: Disabled
Action: None
Maximum Addresses: 0
Содержание SSE-G2252
Страница 42: ...44 General IP Routing on page 627...
Страница 174: ...Chapter 6 VLAN Configuration Configuring VLAN Mirroring 178 Figure 6 27 Showing the VLANs to Mirror...
Страница 511: ...Chapter 14 Basic Administration Protocols UDLD Configuration 518 Figure 14 100 Displaying UDLD Neighbor Information...
Страница 603: ...Chapter 16 IP Configuration Setting the Switch s IP Address IP Version 6 609...
Страница 883: ...Chapter 24 General Security Measures Port based Traffic Segmentation 894...
Страница 989: ...Chapter 30 Congestion Control Commands Automatic Traffic Control Commands 1000 Console...
Страница 1007: ...Chapter 33 Address Table Commands 1019...
Страница 1137: ...Chapter 38 Quality of Service Commands 1150...
Страница 1366: ...Chapter 46 IP Routing Commands Global Routing Configuration 1381 Connected 2 Total 2 FIB 0 Console...