Defining Security Violation Actions - Dell PowerConnect B-RX Configuration Manual

Bigiron rx series configuration guide v02.7.02
Hide thumbs Also See for PowerConnect B-RX:
Table of Contents

Advertisement

32
Configuring the MAC port security feature

Defining security violation actions

A MAC port security violation can occur when a user tries to plug into a port where a MAC address is
already locked, or the maximum number of secure MAC addresses has been exceeded. When a
MAC port security violation occurs, an SNMP trap and Syslog message are generated. Also, you can
configure the device to take any of the following actions when a MAC port security violation occurs:
Violation restrict
The violation restrict action shuts the port down after denying a certain number of violating MAC
addresses. To enable this command, enter the following command.
BigIron RX(config)# int e 7/11
BigIron RX(config-if-e100-7/11)# port security
BigIron RX(config-port-security-e100-7/11)# violation restrict
BigIron RX(config-port-security-e100-7/11)#restrict-max-deny 130
Syntax: violation restrict
Syntax: restrict-max-deny <number>
The violation restrict command enables the violation restrict action.
The restrict-mac-deny command specifies the number of MAC addresses that are to be denied
before the device shuts the port down. Enter 1 – 1024. The default is 128. In the example above,
the port will be shut down after 130 MAC addresses are denied.
Violation shutdown
This violation shutdown action shuts the port down on the first violation. To enable this action,
enter the following command.
BigIron RX(config)# int e 7/11
BigIron RX(config-if-e100-7/11)#port security
BigIron RX(config-port-security-e100-7/11)# violation shutdown
Syntax: violation shutdown
Port shutdown time
When you enable either the violation restrict or violation shutdown action, you can specify how long
the action lasts. For example, you can enter commands such as the following.
BigIron RX(config)# int e 7/11
BigIron RX(config-if-e100-7/11)#port security
BigIron RX(config-port-security-e100-7/11)# violation shutdown
BigIron RX(config-port-security-e100-7/11)#shutdown-time
Syntax: shutdown-time
Enter 0 – 1440 minutes, with 0 as the default. Specifying 0 shuts down the port permanently when
a MAC port security violation occurs.
The shutdown time applies to both the violation restrict and violation shutdown actions.
946
Violation restrict – This action shuts the port down after denying a certain number of violating
MACs
Violation shutdown – This action shuts the port down on the first violation
BigIron RX Series Configuration Guide
53-1001810-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

Brocade dcx-4sBrocade dcx

Table of Contents