Configuration Prerequisites; Configuration Procedure - HPE FlexNetwork 7500 Series Security Configuration Manual

Table of Contents

Advertisement

Type
Address sources
Dynamic
When the maximum number of secure MAC address entries is reached, the port changes to secure
mode. In secure mode, the port cannot add or learn any more secure MAC addresses. The port
allows only frames sourced from secure MAC addresses or MAC addresses configured by using the
mac-address dynamic or mac-address static command to pass through.

Configuration prerequisites

Before you configure secure MAC addresses, complete the following tasks:
Enable port security.
Set port security's limit on the number of MAC addresses on the port. Perform this task before
you enable autoLearn mode.
Set the port security mode to autoLearn.
Configure the port to permit packets of the specified VLAN to pass or add the port to the VLAN.
Make sure the VLAN already exists.

Configuration procedure

To configure a secure MAC address:
Step
1.
Enter system view.
2.
(Optional.) Set the
secure MAC aging
timer.
3.
Configure a secure
MAC address.
dynamic secure MAC
addresses.
Automatically learned
when the dynamic
secure MAC feature is
disabled.
Converted from sticky
MAC addresses.
Automatically learned
after the dynamic
secure MAC feature is
enabled.
Command
system-view
port-security timer autolearn aging
time-value
In system view:
port-security mac-address
security [ sticky ] mac-address
interface interface-type
interface-number vlan vlan-id
In interface view:
a. interface interface-type
interface-number
b. port-security mac-address
security [ sticky ] mac-address
Aging mechanism
configured, the aging timer counts
up regardless of whether traffic
data has been sent from the sticky
MAC addresses.
If both the aging timer and the
inactivity aging feature are
configured, the aging timer restarts
once traffic data is detected from
the sticky MAC addresses.
Same as sticky MAC addresses.
232
Can be saved and
survive a device
reboot?
No.
All dynamic secure
MAC addresses are
lost at reboot.
Remarks
N/A
By default, secure MAC
addresses do not age out.
By default, no manually
configured secure MAC
addresses exist.
In a VLAN, a MAC address cannot
be specified as both a static
secure MAC address and a sticky
MAC address.

Advertisement

Table of Contents
loading

Table of Contents