HP 6600 Security Configuration Manual page 203

Table of Contents

Advertisement

[Router] port-security trap intrusion
[Router] interface gigabitethernet 3/0/1
# Set port security's limit on the number of MAC addresses to 64 on the port.
[Router-GigabitEthernet3/0/1] port-security max-mac-count 64
# Set the port security mode to autoLearn.
[Router-GigabitEthernet3/0/1] port-security port-mode autolearn
# Configure the port to be silent for 30 seconds after the intrusion protection feature is triggered.
[Router-GigabitEthernet3/0/1] port-security intrusion-mode disableport-temporarily
[Router-GigabitEthernet3/0/1] quit
[Router] port-security timer disableport 30
Verifying the configuration
# Display the port security configuration.
<Router> display port-security interface gigabitethernet 3/0/1
Equipment port-security is enabled
Intrusion trap is enabled
AutoLearn aging time is 30 minutes
Disableport Timeout: 30s
OUI value:
GigabitEthernet3/0/1 is link-up
Port mode is autoLearn
NeedToKnow mode is disabled
Intrusion Protection mode is DisablePortTemporarily
Max MAC address number is 64
Stored MAC address number is 5
Authorization is permitted
Security MAC address learning mode is sticky
Security MAC address aging type is absolute
The output shows that the port security's limit on the number of secure MAC addresses on the port is 64,
the port security mode is autoLearn, intrusion protection traps are enabled, and the intrusion protection
action is disabling the port (DisablePortTemporarily) for 30 seconds.
# Repeatedly perform the display port-security command to track the number of MAC addresses learned
by the port, or perform the display this command in interface view to display the learned secure MAC
addresses.
<Router> system-view
[Router] interface gigabitethernet 3/0/1
[Router-GigabitEthernet3/0/1] display this
#
interface GigabitEthernet3/0/1
port-security max-mac-count 64
port-security port-mode autolearn
port-security mac-address security sticky 0002-0000-0015 vlan 1
port-security mac-address security sticky 0002-0000-0014 vlan 1
port-security mac-address security sticky 0002-0000-0013 vlan 1
port-security mac-address security sticky 0002-0000-0012 vlan 1
port-security mac-address security sticky 0002-0000-0011 vlan 1
189

Advertisement

Table of Contents
loading

This manual is also suitable for:

Hsr6600

Table of Contents