Port Security; Introduction; Configuring And Displaying Port Security Settings - Nokia ESB26 User Manual

Gigabit ethernet switch
Table of Contents

Advertisement

6. Port Security

Introduction

You can use port security to block input to a port when the MAC address of the station
attempting to access the port does not match any of the MAC addresses specified for that port.
Alternatively, you can use port security to filter traffic destined to or received from a specific
host based on the host MAC address.
After establishing the maximum number of MAC addresses on a port, the secure MAC
addresses can be configured manually or learned dynamically. You can manually configure
all the secure MAC address or only some of them.
When a secure port receives a packet, the source MAC address of the packet is compared to
the list of secure source addresses that were manually configured or dynamically learned on
the port. If a MAC address of a device attached to the port differs from the list of secure
addresses, the port either shuts down permanently or drops incoming packets from the
insecure host and sends trap message to the Simple Network Management Protocol (SNMP)
manager. The port's behavior depends on the configuration that determines its response to a
security violation.

Configuring and Displaying Port Security Settings

Table 6-1 Port Security Commands
C o m m a n d
port security
show port security
Description of Commands
port security
The port security command, in Interface Configuration mode, enables port security on a port
and restricts the use of the port to a user-defined group of stations. The no form of this
command returns the port to its default value.
If the port security option is activated on a port, only SECURED MAC addresses that are
configured to this port are permitted to connect to this port. A station with a MAC address
that has not been configured appropriately in the MAC address table will produce an address
violation event. See How Entries are added to the FDB.
If no action is defined, the default action is trap. If no maximum number is defined for secure
addresses support, all the addresses will be learned as secured.
MN700004 Rev 01
D e s c r i p t i o n
Enables port security on the configured interface.
Displays the port security configuration.
45

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents