Enabling Port Security; Setting Port Security's Limit On The Number Of Mac Addresses On A Port - H3C S5120-HI Security Configuration Manual

Hide thumbs Also See for S5120-HI:
Table of Contents

Advertisement

Enabling port security

Enabling or disabling port security resets the following security settings to the default:
802.1X access control mode is MAC-based, and the port authorization state is auto.
Port security mode is noRestrictions.
When port security is enabled, you cannot manually enable 802.1X or MAC authentication, or change
the access control mode or port authorization state. The port security automatically modifies these
settings in different security modes.
You cannot disable port security when online users are present.
Before enabling port security, disable 802.1X and MAC authentication globally.
To enable port security:
Step
1.
Enter system view.
2.
Enable port security.
For more information about 802.1X configuration, see
about MAC authentication configuration, see
Setting port security's limit on the number of MAC
addresses on a port
You can set the maximum number of MAC addresses that port security allows on a port for the following
purposes:
Controlling the number of concurrent users on the port. The maximum number of concurrent users on
the port equals this limit or the limit of the authentication mode (802.1X for example) in use,
whichever is smaller.
Controlling the number of secure MAC addresses on the port in autoLearn mode.
The port security's limit on the number of MAC addresses on a port is independent of the MAC learning
limit described in MAC address table configuration in the Layer 2—LAN Switching Configuration Guide.
To set the maximum number of secure MAC addresses allowed on a port:
Step
1.
Enter system view.
2.
Enter Layer 2 Ethernet
interface view.
3.
Set the limit of port security on
the number of MAC
addresses.
Command
system-view
port-security enable
"Configuring
"Configuring MAC
Command
system-view
interface interface-type
interface-number
port-security max-mac-count
count-value
156
Remarks
N/A
By default, the port security is disabled.
802.1X." For more information
authentication."
Remarks
N/A
N/A
Not limited by default.

Advertisement

Table of Contents
loading

Table of Contents