3Com 5500-SI Switch User Manual


 
Ethernet Port Configuration Introduction 63
authenticated devices can obtain data frames from the port so as to prevent illegal
devices from filching network data.
2 Intrusion Protection: By way of checking the source MAC addresses of the data
frames received on a port, this feature discovers illegal packets and takes appropriate
action (temporarily/permanently disabling the port, or filtering out the packets with
these MAC addresses) to guarantee the security on the port.
3 Device Tracking: This feature enables the switch to send trap messages in case special
data packets (generated by special actions such as illegal intrusion, and abnormal user
logon/logoff) pass through a port, thus helping the network administrator monitor
these special actions.
4 Binding of MAC and IP addresses to ports: This feature enables you to bind the MAC
and IP addresses of legal users to specific ports on the switch so that only legal user's
packets can pass through the corresponding ports, thus improving the security of the
system)
Configuring Port Security
Table 47 Configure port security
Operation Command Description
Enter system view system-view -
Enable port security port-security enable Required
Set an OUI value for user
authentication
port-security OUI
OUI-value index
index-value
Optional
Enable the sending of
specified type(s) of trap
messages
port-security trap {
addresslearned |
intrusion | dot1xlogon |
dot1xlogoff |
dot1xlogfailure |
ralmlogon | ralmlogoff |
ralmlogfailure }*
Optional
By default, the system disables the
sending of any types of trap messages.
Enter Ethernet port view interface interface-type
interface-number
-
Set the security mode of the
port
port-security port-mode
mode
Required
You can set different security mode
accordingly.
Set the maximum number of
MAC addresses allowed to
access the port
port-security
max-mac-count
count-value
Optional
By default, there is no limit on the
number of MAC addresses.
Set the packet transmission
mode of the NTK feature on
the port
port-security ntk-mode
{ ntkonly |
ntk-withbroadcasts |
ntk-withmulticasts }
Required
By default, no packet transmission mode
of the NTK feature is set on the port.