62
Protocol Port security
Configuration
Commands
ip portsafe
P
ROTOCOL
C
ONFIGURATION
Syntax
ip portsafe enable
undo ip portsafe enable
View
System view
Parameter
None
Description
Use the ip portsafe enable command to enable the protocol port security
function to check all IP packets on the interface module. If the destination IP is the
virtual interface IP of the switch, and the corresponding destination protocol port
is not open, the packet will be dropped.
Use the undo ip portsafe enable command to disable the protocol port security
function. Then all packets on the interface module are not checked.
By default, the fabric enables the protocol port security function. So do the
standby module and the interface module.
At present, the following protocols are being checked:
Table 153 State of the protocol port
Protocol
IGMP/IGSP
OSPF
PIM
SSH
TELNET
HTTP
BGP
MPLS LDP
P
S
ORT
ECURITY
C
OMMANDS
Port
PROTOCOL:2
PROTOCOL:89
PROTOCOL:123
TCP:22
TCP:23
TCP:80
TCP:179
TCP:646
Default State
Close
Close
Close
Close
Close
Open
Close
Close