Dell PowerConnect J-EX4200-24T Software Manual page 2664

J series; j-ex series
Table of Contents

Advertisement

Dell PowerConnect J-Series Ethernet Switch Complete Software Guide for Junos OS
Table 326: Components of the Port Security Topology (continued)
Properties
Interface for DHCP server
Configuration
CLI Quick
Configuration
Step-by-Step
Procedure
Results
Verification
Purpose
2592
Settings
ge-0/0/8
In this example, the switch has already been configured as follows:
Secure port access is activated on the switch.
DHCP snooping is enabled on the VLAN
All access ports are untrusted, which is the default setting.
To configure allowed MAC addresses to protect the switch against DHCP snooping
database alteration attacks:
To quickly configure some allowed MAC addresses on an interface, copy the following
commands and paste them into the switch terminal window:
[edit ethernet-switching-options secure-access-port]
set interface ge-0/0/2 allowed-mac 00:05:85:3A:82:80
set interface ge-0/0/2 allowed-mac 00:05:85:3A:82:81
set interface ge-0/0/2 allowed-mac 00:05:85:3A:82:83
set interface ge-0/0/2 allowed-mac 00:05:85:3A:82:85
set interface ge-0/0/2 allowed-mac 00:05:85:3A:82:88
To configure some allowed MAC addresses on an interface:
Configure the five allowed MAC addresses on an interface:
[edit ethernet-switching-options secure-access-port]
user@switch# set interface ge-0/0/2 allowed-mac 00:05:85:3A:82:80
user@switch# set interface ge-0/0/2 allowed-mac 00:05:85:3A:82:81
user@switch# set interface ge-0/0/2 allowed-mac 00:05:85:3A:82:83
user@switch# set interface ge-0/0/2 allowed-mac 00:05:85:3A:82:85
user@switch# set interface ge-0/0/2 allowed-mac 00:05:85:3A:82:88
Check the results of the configuration:
[edit ethernet-switching-options secure-access-port]
user@switch# show
interface ge-0/0/2.0 {
allowed-mac [ 00:05:85:3a:82:80 00:05:85:3a:82:81 00:05:85:3a:82:83 00:05:85
:3a:82:85 00:05:85:3a:82:88 ];
}
To confirm that the configuration is working properly:
Verifying That Allowed MAC Addresses Are Working Correctly on the Switch on page 2592
Verifying That Allowed MAC Addresses Are Working Correctly on the Switch
Verify that allowed MAC addresses are working on the switch.
employee-vlan
.

Advertisement

Table of Contents
loading

Table of Contents