Port Security Features; Port Security Modes - 3Com 4510G Configuration Manual

3com switch 4510g family
Table of Contents

Advertisement

Port Security Features

NTK
The need to know (NTK) feature checks the destination MAC addresses in outbound frames and
allows frames to be sent to only devices passing authentication, thus preventing illegal devices from
intercepting network traffic.
Intrusion protection
The intrusion protection feature checks the source MAC addresses in inbound frames and takes a
pre-defined action accordingly upon detecting illegal frames. The action may be disabling the port
temporarily, disabling the port permanently, or blocking frames from the MAC address for three
minutes (unmodifiable).
Trap
The trap feature enables the device to send trap messages upon detecting specified frames that result
from, for example, intrusion or user login/logout operations, helping you monitor special activities.

Port Security Modes

Table 6-1
details the port security modes.
Table 6-1 Port security modes
Security mode
noRestrictions
autoLearn
secure
userLogin
Description
Port security is disabled on the port and access to
the port is not restricted.
In this mode, a port can learn a specified number
of MAC addresses and save those addresses as
secure MAC addresses. It permits only frames
whose source MAC addresses are secure MAC
addresses or static MAC addresses configured by
using the mac-address static command.
When the number of secure MAC addresses
reaches the upper limit, the port changes to work
in secure mode.
In this mode, a port is disabled from learning
MAC addresses and permits only frames whose
source MAC addresses are secure MAC
addresses or static MAC addresses configured by
using the mac-address static command.
In this mode, a port performs 802.1X
authentication of users in portbased mode.
A port in this mode can service multiple 802.1X
users, but allows only one at a moment.
6-2
Features
In this mode, neither
the NTK nor the
intrusion protection
feature is triggered.
In either mode, the
device will trigger NTK
and intrusion protection
upon detecting an
illegal frame.
In this mode, neither
NTK nor intrusion
protection will be
triggered.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents