Configuring Secure Mac Addresses; Configuration Prerequisites - HP 3600 v2 Series Security Configuration Manual

Hide thumbs Also See for 3600 v2 Series:
Table of Contents

Advertisement

Configuring secure MAC addresses

Secure MAC addresses are configured or learned in autoLearn mode and can survive link down/up
events. You can bind a secure MAC address to only one port in a VLAN.
Secure MAC addresses fall into static, sticky and dynamic secure MAC addresses.
Table 11 A comparison of static, sticky, and dynamic secure MAC addresses
Type
Static
Sticky
Dynamic
IMPORTANT:
When the maximum number of secure MAC address entries is reached, the port changes to secure mode,
and no more secure MAC addresses can be added or learned. The port allows only frames sourced from
a secure MAC address or a MAC address configured by using the mac-address dynamic or mac-address
static command to pass through.

Configuration prerequisites

Enable port security.
Set port security's limit on the number of MAC addresses on the port. Perform this task before you
enable autoLearn mode.
Set the port security mode to autoLearn.
Address sources
Aging mechanism
Not available.
They never age out unless you manually remove
Manually added
them, change the port security mode, or disable
the port security feature.
They do not age out by default, but you can
configure the following aging functions:
Manually added or
automatically learned
when the dynamic
secure MAC function
is disabled.
Converted from sticky
MAC addresses or
automatically learned
Same as sticky MAC addresses.
after the dynamic
secure MAC function
is enabled.
Aging timer—A sticky MAC address ages
out when its aging timer expires, but whether
it is immediately deleted depends on the
aging delay setting.
Aging delay—If aging delay is disabled, the
system deletes the sticky MAC address
immediately after the aging timer expires. If
aging delay is enabled, the system deletes
the sticky MAC address if no data traffic is
from the secure source MAC address before
the delay expires.
208
Can be saved and
survive a device
reboot?
Yes.
Yes.
The secure MAC aging
timer restarts at a
reboot.
No.
All dynamic secure
MAC addresses are
lost at reboot.

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

A3100-48 v2

Table of Contents