Port Security Modes - HP 3600 v2 Series Configuration Manual

Hide thumbs Also See for 3600 v2 Series:
Table of Contents

Advertisement

Port security modes

Port security supports the following categories of security modes:
MAC learning control—Includes two modes, autoLearn and secure. MAC address learning is
permitted on a port in autoLearn mode and disabled in secure mode.
Authentication—Security modes in this category implement MAC authentication, 802.1X
authentication, or a combination of these two authentication methods.
Upon receiving a frame, the port in a security mode searches the MAC address table for the source MAC
address. If a match is found, the port forwards the frame. If no match is found, the port learns the MAC
address or performs authentication, depending on the security mode. If the frame is illegal, the port takes
the pre-defined NTK, intrusion protection, or trapping action.
The maximum number of users a port supports equals the maximum number of MAC addresses that port
security allows or the maximum number of concurrent users the authentication mode in use allows,
whichever is smaller. For example, if 802.1X allows more concurrent users than port security's limit on the
number of MAC addresses on the port in userLoginSecureExt mode, port security's limit takes effect.
Table 13
describes the port security modes and the security features.
Table 13 Port security modes
Purpose
Turning off the port security
feature
Controlling MAC address
learning
Performing 802.1X
authentication
Performing MAC authentication
Performing a combination of
MAC authentication and
802.1X authentication
Security mode
noRestrictions (the default mode)
In this mode, port security is disabled on the port
and access to the port is not restricted.
autoLearn
secure
userLogin
userLoginSecure
userLoginSecureExt
userLoginWithOUI
macAddressWithRadius
macAddressOrUserLoginSecure
Or
macAddressOrUserLoginSecureExt
macAddressElseUserLoginSecure
Else
macAddressElseUserLoginSecureExt
198
Features that can be
triggered
N/A
NTK/intrusion
protection
N/A
NTK/intrusion
protection
NTK/intrusion
protection
NTK/intrusion
protection

Advertisement

Table of Contents
loading

Table of Contents