H3C S3100 Series Command Manual page 230

Hide thumbs Also See for S3100 Series:
Table of Contents

Advertisement

Command Manual ( For Soliton ) – Port Security-Port Binding
H3C S3100 Series Ethernet Switches
disableport-temporarily: Disables a port for a specified period of time after an illegal
frame or event is detected on it. You can set the period with the port-security timer
disableport command.
Description
Use the port-security intrusion-mode command to set intrusion protection.
Use the undo port-security intrusion-mode command to disable intrusion protection.
By default, intrusion protection is not configured.
Note:
By checking the source MAC addresses in inbound data frames or the username and
password in 802.1x authentication requests on a port, intrusion protection detects
illegal packets (packets with illegal MAC address) or events and takes a pre-set action
accordingly.
temporarily/permanently and blocking packets with invalid MAC addresses.
The following cases can trigger intrusion protection on a port:
A packet with unknown source MAC address is received on the port while MAC
address learning is disabled on the port.
A packet with unknown source MAC address is received on the port while the
amount of security MAC addresses on the port has reached the preset maximum
number.
The user fails the 802.1x or MAC address authentication.
After executing the port-security intrusion-mode blockmac command, you can only
use the display port-security command to view blocked MAC addresses.
Related commands: display port-security, port-security timer disableport.
Examples
# Configure the intrusion protection mode on Ethernet 1/0/1 as blockmac.
<Sysname> system-view
System View: return to User View with Ctrl+Z.
[Sysname] interface Ethernet 1/0/1
[Sysname-Ethernet1/0/1] port-security intrusion-mode blockmac
# Display information about blocked MAC addresses after intrusion protection is
triggered.
<Sysname> display port-security
Equipment port-security is enabled
AddressLearn trap is Enabled
Intrusion trap is Enabled
The
actions
you
1-9
Chapter 1 Port Security Commands
can
set
include:
disconnecting
the
port

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents