3Com 5104M-FIB Switch User Manual


 
SET SECURITY_ADVANCED NETWORK SOURCE_PORT_ CHECKING
2-247
SET
SECURITY_ADVANCED
NETWORK
SOURCE_PORT_
CHECKING
Use the SET SECURITY_ADVANCED NETWORK SOURCE_PORT_CHECKING
command to enable source port checking on an Ethernet network that has a
Ethernet Private Line Card assigned to it.
When you enable source port checking, the source port number and MAC
address of each packet transmitted on a secure network is checked against an
established list of valid port numbers and MAC addresses in the security address
table. If the source port number and MAC address of the packet does not
match the port number and MAC address in the security table, the packet is
treated as an intruder.
If you enable source port checking on your network, only ports with intruder
checking enabled are looked up in the security address table.
When you enable source port checking, the Ethernet Private Line Card enables
source address checking automatically.
Format
Example
The following command enables source port checking on ethernet_1:
CB5000> set security_advanced network ethernet_1
source_port_checking enable
ETHERNET_1 Source Port Checking: set to ENABLED.
Related Command
SHOW SECURITY_ADVANCED
ethernet_
1...8
Specifies which Ethernet network to apply this command.
isolated_
1...8
Specifies which isolated network to apply this command.
enable
Enables source port checking.
disable
Disables source port checking.
set security_advanced network
enableethernet_
1...8
source_port_checking
disable
isolated_
1...8