Port Security; Mac-Learning; Table 86: Port Security Commands - Edge-Core ECS3510-28T Management Manual

Edge-core 28/52-port fast ethernet layer 2 switch
Table of Contents

Advertisement

| General Security Measures
C
24
HAPTER

Port Security

P
S
ORT
ECURITY

mac-learning

These commands can be used to enable port security on a port.
When MAC address learning is disabled on an interface, only incoming
traffic with source addresses already stored in the dynamic or static
address table for this port will be authorized to access the network.
When using port security, the switch stops learning new MAC addresses on
the specified port when it has reached a configured maximum number.
Only incoming traffic with source addresses already stored in the dynamic
or static address table for this port will be authorized to access the
network. The port will drop any incoming frames with a source MAC
address that is unknown or has been previously learned from another port.
If a device with an unauthorized MAC address attempts to use the switch
port, the intrusion will be detected and the switch can automatically take
action by disabling the port and sending a trap message.

Table 86: Port Security Commands

Command
Function
mac-address-table static
Maps a static address to a port in a VLAN
mac-learning
Enables MAC address learning on the selected physical
interface or VLAN
port security
Configures a secure port
port security
Saves the MAC addresses learned by port security as
mac-address-as-
static entries.
permanent
show mac-address-table
Displays entries in the bridge-forwarding database
show port security
Displays port security status and secure address count
This command enables MAC address learning on the selected interface. Use
the no form to disable MAC address learning.
S
YNTAX
[no] mac-learning
D
S
EFAULT
ETTING
Enabled
C
M
OMMAND
ODE
Interface Configuration (Ethernet or Port Channel)
C
U
OMMAND
SAGE
The no mac-learning command immediately stops the switch from
learning new MAC addresses on the specified port or trunk. Incoming
traffic with source addresses not stored in the static address table, will
be flooded. However, if a security function such as 802.1X or DHCP
snooping is enabled and mac-learning is disabled, then only incoming
– 866 –
Mode
GC
IC
IC
PE
PE
PE

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ecs3510-52t

Table of Contents