Enterasys Networks E1 Series Network Router User Manual


 
Security Configuration Command Set
Configuring MAC Locking
Matrix E1 Series (1G58x-09 and 1H582-xx) Configuration Guide 14-43
14.3.4 Configuring MAC Locking
Purpose
To review, disable, enable and configure MAC locking. This locks a port to one or more MAC
addresses, preventing connection of unauthorized devices via the port(s). When source MAC
addresses are received on specified ports, the switch discards all subsequent frames not containing
the configured source addresses. The only frames forwarded on a “locked” port are those with the
“locked” MAC address(es) for that port.
Commands
The commands needed to configure MAC locking are listed below and described in the associated
section as shown:
show maclock (Section 14.3.4.1)
show maclock stations (Section 14.3.4.2)
set maclock enable (Section 14.3.4.3)
set maclock disable (Section 14.3.4.4)
set maclock (Section 14.3.4.5)
set maclock firstarrival (Section 14.3.4.6)
set maclock static (Section 14.3.4.7)
set maclock move (Section 14.3.4.8)
clear maclock static (Section 14.3.4.9)
show maclock autostatic (Section 14.3.4.10)
set maclock autostatic (Section 14.3.4.11)
set maclock autostatic isl (Section 14.3.4.12)
set maclock autostatic publicvlan (Section 14.3.4.13)
set maclock autostatic publicmac (Section 14.3.4.14)
set maclock autostatic passthroughmac (Section 14.3.4.15)
NOTE: The Matrix E1 MAC locking commands have no direct interdependencies with
the MAC authentication commands described in Section 14.3.3. When a frame arrives
at a port, the Matrix E1 device runs the MAC locking algorithm first. If the frame passes
the MAC lock (i.e., it is not in violation), then the frame is eligible for authentication.