Configuring Port Security; Establishing The Configuration Task - Huawei Quidway S7700 Configuration Manual - Ethernet

Smart routing switch
Hide thumbs Also See for Quidway S7700:
Table of Contents

Advertisement

Quidway S7700 Smart Routing Switch
Configuration Guide - Ethernet
Procedure
Step 1 Run the display mac-limit [ interface-type interface-number | vlan vlan-id | vsi vsi-name |
slot slot-id ] command to view the MAC address limiting rule.
----End

7.8 Configuring Port Security

The port security function prevents devices with untrusted MAC addresses from accessing an
interface. This function is applicable to the networks that require high access security.

7.8.1 Establishing the Configuration Task

The port security function changes MAC addresses learned by an interface to secure dynamic
MAC addresses or sticky MAC addresses. It prevents devices with untrusted MAC addresses
from accessing an interface and improves device security.
Applicable Environment
If a network requires high access security, you can configure port security on specified interfaces.
MAC addresses learned by these interfaces change to secure dynamic MAC addresses or sticky
MAC addresses. When the number of learned MAC addresses reaches the limit, the interface
does not learn new MAC addresses and allows only the devices with the learned MAC addresses
to communicate with the S7700. This prevents devices with untrusted MAC addresses from
accessing these interfaces, improving security of the S7700 and the network.
Pre-configuration Tasks
Before configuring port security on an interface, complete the following tasks:
l
l
l
l
l
Data Preparation
To configure port security on an interface, you need the following data.
No.
1
2
Issue 01 (2011-07-15)
Disabling MAC address limiting on the interface
Disabling MUX VLAN on the interface
Disabling MAC address authentication on the interface
Disabling 802.1x authentication on the interface
Disabling MAC address security for DHCP snooping on the interface
Data
Secure dynamic MAC: interface type and number, limit on the number of learned
MAC addresses, action to perform when the limit is exceeded
Sticky MAC: interface type and number, limit on the number of learned MAC
addresses, and action to perform when the limit is exceeded
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
7 MAC Address Table Configuration
358

Advertisement

Table of Contents
loading

This manual is also suitable for:

Quidway s9300

Table of Contents