Allowing Mac Addresses - GE Multilink ML3000 Instruction Manual

Ethernet communications switch
Table of Contents

Advertisement

ACCESS CONSIDERATIONS
Note
NOTE
Note
NOTE
6.2.2

Allowing MAC Addresses

Note
NOTE
6–4
- removes specific or all MAC addresses from port security lookup
remove mac
signal port=<num|list|range>
there is a security breach on the list of port specified. The signal can be a log entry,
a trap to the trap receiver specified as part of the SNMP commands (where is that
specified) or both
There is a limitation of 200 MAC addresses per port and 500 MAC addresses per switch for
port security.
All commands listed above must be executed under the port security configuration mode.
Let's look at a few examples. The following command allows specific MAC addresses on a
specified port. No spaces are allowed between specified MAC addresses.
ML3000(port-security)##
mac=00:c1:00:7f:ec:00,00:60:b0:88:9e:00 port=18
The following command sequence sets the port security to learn the MAC addresses. Note
that a maximum of 200 MAC addresses can be learned per port, to a maximum of 500 per
switch. Also, the
on the port must be set to none before the port learns the MAC
action
address information.
ML3000(port-security)##
ML3000(port-security)##
The following command sequence enables and disables port security
ML3000(port-security)##
Port Security is already enabled
ML3000(port-security)##
Port Security Disabled
ML3000
ps enable
Port Security Enabled
The Port Security feature has to be used with the combination of commands shown below
in order for it to be implemented successfully.
To configure a port to allow only a certain MAC address (single or a list of max 200 MAC
addresses per port and 500 MAC addresses per ML3000, as per manuals) we have to:
1.
Verify that the port is in default port security status.
2.
Use the following commands:
#port-security
(port-security)##ps enable
(port-security)##allow mac=<address,list,range> port=<num,list,range>
(port-security)##action port=<num,list,range>drop
All the above commands have to be configured in this sequence, otherwise the port will
remain insecure.
MULTILINK ML3000 ETHERNET COMMUNICATIONS SWITCH – INSTRUCTION MANUAL
CHAPTER 6: ACCESS CONSIDERATIONS
- observe list of specified ports and notify if
allow
action port=9,10 none
learn port=9,10 enable
ps enable
ps disable

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents