Configuration Procedure; Setting Port Security's Limit On The Number Of Mac Addresses For Specific Vlans On A Port; Overview - HPE FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Configure the port to permit packets of the specified VLAN to pass or add the port to the VLAN.
Make sure the VLAN already exists.

Configuration procedure

To configure a secure MAC address:
Step
1.
Enter system view.
2.
(Optional.) Set the
secure MAC aging
timer.
3.
Configure a secure
MAC address.
4.
Enter Layer 2 Ethernet
interface view.
5.
(Optional.) Enable
inactivity aging.
6.
(Optional.) Enable the
dynamic secure MAC
feature.
Setting port security's limit on the number of MAC
addresses for specific VLANs on a port

Overview

Typically, port security allows the access of the following types of MAC addresses:
MAC addresses that pass MAC authentication or 802.1X authentication.
MAC addresses in the MAC authentication guest VLAN or MAC authentication critical VLAN
and MAC addresses in the MAC authentication guest VSI or MAC authentication critical VSI.
MAC addresses in the 802.1X guest VLAN, 802.1X Auth-Fail VLAN, or 802.1X critical VLAN
and MAC addresses in the 802.1X guest VSI, 802.1X Auth-Fail VSI, or 802.1X critical VSI.
This feature limits the number of MAC addresses that port security allows to access a port through
specific VLANs. Use this feature to prevent resource contentions among MAC addresses and
ensure reliable performance for each access user on the port. When the number of MAC addresses
in a VLAN on the port reaches the upper limit, the device denies any subsequent MAC addresses in
the VLAN on the port.
Command
system-view
port-security timer autolearn aging
[ second ] time-value
In system view:
port-security mac-address
security [ sticky ] mac-address
interface interface-type
interface-number vlan vlan-id
In Layer 2 Ethernet interface view:
a. interface interface-type
interface-number
b. port-security mac-address
security [ sticky ] mac-address
vlan vlan-id
c. quit
interface interface-type
interface-number
port-security mac-address
aging-type inactivity
port-security mac-address dynamic
249
Remarks
N/A
By default, secure MAC
addresses do not age out.
By default, no manually
configured secure MAC
addresses exist.
In a VLAN, a MAC address cannot
be specified as both a static
secure MAC address and a sticky
MAC address.
N/A
By default, the inactivity aging
feature is disabled.
By default, the dynamic secure
MAC feature is disabled. Sticky
MAC addresses can be saved to
the configuration file. Once saved,
they can survive a device reboot.

Advertisement

Table of Contents
loading

Table of Contents