H3C S6812 Series Command Reference Manual page 1906

Hide thumbs Also See for S6812 Series:
Table of Contents

Advertisement

Usage guidelines
To change the security mode for a port security enabled port, you must set the port in noRestrictions
mode first. Do not change port security mode when the port has online users.
IMPORTANT:
If you are configuring the autoLearn mode, first set port security's limit on the number of secure
MAC addresses by using the port-security max-mac-count command. You cannot change the
setting when the port is operating in autoLearn mode.
When port security is enabled, you cannot enable 802.1X or MAC authentication, or change the
access control mode or port authorization state. The port security automatically modifies these
settings in different security modes.
As
a
best
mac-else-userlogin-secure-ext mode on the port where MAC authentication delay is enabled. The
two modes are mutually exclusive with the MAC authentication delay feature. For more information
about MAC authentication delay, see "MAC authentication commands."
Examples
# Enable port security, and set Ten-GigabitEthernet 1/0/1 to operate in secure mode.
<Sysname> system-view
[Sysname] port-security enable
[Sysname] interface ten-gigabitethernet 1/0/1
[Sysname-Ten-GigabitEthernet1/0/1] port-security port-mode secure
# Change the port security mode of Ten-GigabitEthernet 1/0/1 to userLogin.
[Sysname-Ten-GigabitEthernet1/0/1] undo port-security port-mode
[Sysname-Ten-GigabitEthernet1/0/1] port-security port-mode userlogin
Related commands
display port-security
port-security max-mac-count
port-security timer autolearn aging
Use port-security timer autolearn aging to set the secure MAC aging timer.
Use undo port-security timer autolearn aging to restore the default.
Syntax
port-security timer autolearn aging time-value
undo port-security timer autolearn aging
Default
Secure MAC addresses do not age out.
Views
System view
Predefined user roles
network-admin
Parameters
time-value: Specifies the aging timer in minutes for secure MAC addresses. The value is in the
range of 0 to 129600. To disable the aging timer, set the timer to 0.
practice,
do
not
enable
the
mac-else-userlogin-secure
18
or

Advertisement

Table of Contents
loading

This manual is also suitable for:

S6813 seriesS5150-ei

Table of Contents