Port Security - Tripp Lite NGI-S04C2 Owner's Manual

4 10/100/1000base-t ports+2 100fx/gigabit sfp slots lite managed industrial ethernet switch
Table of Contents

Advertisement

Mask of Source IP
Destination IP
Mask of
Destination IP
Source Application
Destination
Application
Source Interface(s)
Apply
Refresh

6.3. Port Security

The Switch will learn the MAC address of the device directly connected to a particular
port and allow traffic through. We will ask the question: "How do we control who and
how many can connect to a switch port?" This is where port security can assist us. The
Switch allow us to control which devices can connect to a switch port or how many of
them can connect to it (such as when a hub or another switch is connected to the port).
Let's say we have only one switch port left free and we need to connect five hosts to it.
What can we do? Connect a hub or switch to the free port! Connecting a switch or a hub
to a port has implications. It means that the network will have more traffic. If a switch or
a hub is connected by a user instead of an administrator, then there are chances that loops
will be created. So, it is best that number of hosts allowed to connect is restricted at the
switch level. This can be done using the "port-security limit" command. This command
configures the maximum number of MAC addresses that can source traffic through a
port.
Port security can sets maximum number of MAC addresses allowed per interface. When
the limit is exceeded, incoming packets with new MAC addresses are dropped. It can be
use MAC table to check it. The static MAC addresses are included for the limit.
Configures the bitmap mask of the source IP of the packets that
you want to filter.
If the Source IP field has been configured and this field is
empty, it means the profile will filter the one IP configured in
Source IP field.
Configures the destination IP of the packets that you want to
filter.
Configures the bitmap mask of the destination IP of the packets
that you want to filter.
If the Destination IP field has been configured and this field is
empty, it means the profile will filter the one IP configured in
Destination IP field.
Configures the source UDP/TCP ports of the packets that you
want to filter.
Configures the destination UDP/TCP ports of the packets that
you want to filter.
Configures one or a rage of the source interfaces of the packets
that you want to filter.
Click Apply to add/modify the settings.
Click Refresh to begin configuring this screen afresh.
91

Advertisement

Table of Contents
loading

Table of Contents