Chapter 24: General Security Measures
Port Security
– 818 –
P
ORT
S
ECURITY
These commands can be used to enable port security on a port.
When MAC address learning is disabled on an interface, only incoming
traffic with source addresses already stored in the dynamic or static
address table for this port will be authorized to access the network.
When using port security, the switch stops learning new MAC addresses on
the specified port when it has reached a configured maximum number.
Only incoming traffic with source addresses already stored in the dynamic
or static address table for this port will be authorized to access the
network. The port will drop any incoming frames with a source MAC
address that is unknown or has been previously learned from another port.
If a device with an unauthorized MAC address attempts to use the switch
port, the intrusion will be detected and the switch can automatically take
action by disabling the port and sending a trap message.
mac-learning
This command enables MAC address learning on the selected interface. Use
the
no
form to disable MAC address learning.
S
YNTAX
[
no
]
mac-learning
D
EFAULT
S
ETTING
Enabled
C
OMMAND
M
ODE
Interface Configuration (Ethernet or Port Channel)
C
OMMAND
U
SAGE
•
The
no mac-learning
command immediately stops the switch from
learning new MAC addresses on the specified port or trunk. Incoming
traffic with source addresses not stored in the static address table, will
be flooded. However, if a security function such as 802.1X or DHCP
Table 24-2: Management IP Filter Commands
Command
Function
Mode
Maps a static address to a port in a VLAN
GC
Enables MAC address learning on the selected VLAN
GC
Enables MAC address learning on the selected physical
interface
IC
Configures a secure port
IC
Saves the MAC addresses learned by port security as
static entries.
PE
Displays entries in the bridge-forwarding database
PE
Displays port security status and secure address count
PE
Содержание SSE-G2252
Страница 42: ...44 General IP Routing on page 627...
Страница 174: ...Chapter 6 VLAN Configuration Configuring VLAN Mirroring 178 Figure 6 27 Showing the VLANs to Mirror...
Страница 511: ...Chapter 14 Basic Administration Protocols UDLD Configuration 518 Figure 14 100 Displaying UDLD Neighbor Information...
Страница 603: ...Chapter 16 IP Configuration Setting the Switch s IP Address IP Version 6 609...
Страница 883: ...Chapter 24 General Security Measures Port based Traffic Segmentation 894...
Страница 989: ...Chapter 30 Congestion Control Commands Automatic Traffic Control Commands 1000 Console...
Страница 1007: ...Chapter 33 Address Table Commands 1019...
Страница 1137: ...Chapter 38 Quality of Service Commands 1150...
Страница 1366: ...Chapter 46 IP Routing Commands Global Routing Configuration 1381 Connected 2 Total 2 FIB 0 Console...