Step
1.
Enter system view.
2.
Enable port security.
You can use the undo port-security enable command to disable port security when no online users
are present.
Enabling or disabling port security resets the following security settings to the default:
•
802.1X access control mode is MAC-based, and the port authorization state is auto.
•
Port security mode is noRestrictions.
For more information about Configuring 802.1X, see "Configuring 802.1X."
For more information about MAC authentication configuration, see "Configuring MAC
authentication."
Setting port security's limit on the number of MAC
addresses on a port
You can set the maximum number of MAC addresses that port security allows on a port for the
following purposes:
•
Controlling the number of concurrent users on the port. The maximum number of concurrent
users on the port equals this limit or the limit of the authentication mode (802.1X for example) in
use, whichever is smaller.
•
Controlling the number of secure MAC addresses on the port in autoLearn mode.
The port security's limit on the number of MAC addresses on a port is independent of the MAC
learning limit described in MAC address table configuration in the Layer 2—LAN Switching
Configuration Guide.
To set the maximum number of secure MAC addresses allowed on a port:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Set the limit of port security
on the number of MAC
addresses.
Setting the port security mode
The following matrix shows the autoLearn, secure and userLogin modes on Layer 2 Ethernet ports
and hardware compatibility:
Hardware
MSR900
MSR93X
Command
system-view
port-security enable
Command
system-view
interface interface-type
interface-number
port-security max-mac-count
count-value
Port security mode compatibility
autoLearn
No
No
Remarks
N/A
The port security is disabled.
secure
No
No
130
Remarks
N/A
N/A
Not limited by default.
userLogin
Yes
Yes
Need help?
Do you have a question about the FlexNetwork MSR Series and is the answer not in the manual?