
3-10 AT-8600 Series Software Reference
Software Release 2.6.4
C613-03081-00 REV A
Port security
The port security feature allows control over the stations connected to each
switch port, by MAC address. If enabled on a port, the switch learns MAC
addresses up to a user-defined limit from 1 to 256, then locks out all other MAC
addresses. One of the following options can be specified for the action taken
when an unknown MAC address is detected on a locked port:
■ Discard the packet and take no further action,
■ Discard the packet and notify management with an SNMP trap,
■ Discard the packet, notify management with an SNMP trap and disable the
port.
To enable port security on a port, set the limit for learned MAC addresses to a
value greater than zero, and specify the action to take for unknown MAC
addresses on a locked port. To disable port security on a port, set the limit for
learned MAC addresses to zero or NONE. Port security can be enabled or
disabled on a port using the command:
SET SWITCH PORT={port-list|ALL} LEARN={NONE|0|1..256}
[INTRUSIONACTION={DISCARD|TRAP|DISABLE}]
If INTRUSIONACTION is set to TRAP or DISABLE, a list of MAC addresses
for devices that are active on a port, but which are not allowed or learned for
the port, can be displayed (Figure 3-25 on page 3-147) using the command:
SHOW SWITCH PORT={port-list|ALL} INTRUSION
A switch port can be manually locked before it reaches the learning limit by
using the command:
ACTIVATE SWITCH PORT={port-list|ALL} LOCK
Addresses can be manually added to a port locked list up to a total of 256 MAC
addresses, and the learning limit can be extended to accommodate them. Use
the command:
ADD SWITCH FILTER ACTION={FORWARD|DISCARD} DESTADDRESS=macadd
PORT=port [ENTRY=entry] [LEARN] [VLAN={vlan-name|1..4094}]
Learned addresses on locked ports can be saved as part of the switch
configuration, so that they become part of the configuration after a power
cycle. Use the command:
CREATE CONFIG=filename
If the configuration is not saved when there is a locked list for a port, the
learning process begins again after the router is restarted.
Comentários a estes Manuais