Port And Link Aggregate Security Violation - Alcatel-Lucent OmniSwitch AOS Release 7 Manual

Network configuration guide
Hide thumbs Also See for OmniSwitch AOS Release 7:
Table of Contents

Advertisement

Learned Port Security Overview

Port and Link Aggregate Security Violation

A port-security violation is triggered when the switch exceeds the limit for the maximum number of MAC
addresses learnt. There are different types of violations:
LPS violations
QoS Policy violations
Network Security violations
UDLD violations
Fabric stability related violations
A security violation occurs under the following conditions:
a port is configured as a secure port and the number of secure MAC addresses learnt on the port has
exceeded the maximum value.
a workstation with a secure MAC address that is configured or learned on one of the secure ports,
attempts to access another secure port.
Security violations on Link Aggregates:
When a violation occurs on a physical port that is part of a link aggregate, it affects the entire link
aggregate group. All ports on that link aggregate are either restricted or shut down.
When the violations are cleared for the whole link aggregate group using the
the whole link aggregate group is reactivated.
When a simulated down violation is listed, toggling the link clears the violation, for both the link
aggregates and physical ports.
A specific action is taken when a violation is detected on the port. Depending on the type of violation, two
types of actions are associated with the shutdown of a port:
admin down - deactivates the physical port. This action is taken for a UDLD violation.
simulated down - the physical port shows as active but the applications are not allowed to access the
port link. The port is put in blocking state.
The LPS violations on individual ports or link aggregates can be viewed using the
command.
Note.
The source learning time limit is configured on the LPS ports, using the
window
command.
Use the
clear violation
session and activate the ports.
page 25-8
command to clear all the MAC address violation logs for a particular port and
OmniSwitch AOS Release 7 Network Configuration Guide
Configuring Learned Port Security
clear violation
command,
show violation
port-security learning-
March 2011

Advertisement

Table of Contents
loading

This manual is also suitable for:

Omniswitch aos 7

Table of Contents