Configuring Learned Port Security
Sample Learned Port Security Configuration
This section provides a quick tutorial that demonstrates the following tasks:
Enabling LPS on a set of switch ports.
•
Defining the maximum number of learned MAC addresses allowed on an LPS port.
•
Defining the time limit in which source learning is allowed on all LPS ports.
•
Selecting a method for handling unauthorized traffic received on an LPS port.
•
Note that LPS is supported on 10/100 and gigabit Ethernet fixed, mobile, tagged and authenticated ports.
Link aggregate and tagged (trunked) link aggregate ports are not eligible for LPS monitoring and control.
1
Enable LPS on ports 6 through 12 on slot 3, 4, and 5 using the following command:
-> port-security 3/6-12 4/6-12 5/6-12 enable
2
Set the total number of learned MAC addresses allowed on the same ports to 25 using the following
command:
-> port-security 3/6-12 4/6-12 5/6-12 maximum 25
3
Configure the amount of time in which source learning is allowed on all LPS ports to 30 minutes using
the following command:
-> port-security shutdown 30
4
Select shutdown for the LPS violation mode using the following command:
-> port-security 3/6-12 4/6-12 5/6-12 violation shutdown
Note. Optional. To verify LPS port configurations, use the
-> show port-security
Port Security MaxMacs Violation
----+--------+-------+---------+-----------------+-------------------+-----------------+-----------
2/2
enabled
25
4/8
enabled
100
6/1
enabled
10
6/5
enabled
100
To verify the new source learning time limit value, use the
example:
-> show port-security shutdown
LPS Shutdown = 30
OmniSwitch 6624/6648 Network Configuration Guide
LowMac
restrict
00:20:95:00:00:10
shutdown
00:00:00:00:00:00
shutdown
00:00:00:00:00:00
restrict
00:00:00:00:00:00
Sample Learned Port Security Configuration
show
port-security. For example:
HighMac
IndividualMac
00:20:95:00:00:20
ff:ff:ff:ff:ff:ff
00:da:92:3a:59:0c
ff:ff:ff:ff:ff:ff
00:da:92:4b:6a:1d
00:da:92:5c:7b:2e
ff:ff:ff:ff:ff:ff
00:da:92:00:1a:20
show port-security shutdown
April 2004
MacType
configured
dynamic
dynamic
configured
command. For
page 3-3