3Com 3C17300A Implementation Guide - Page 78

Port Security, Continuous Learning, Automatic Learning, Learning Off, Network Login

Page 78 highlights

78 CHAPTER 10: MAKING YOUR NETWORK SECURE Port Security The Switch supports the following port security modes, which you can set for an individual port or a range of ports: ■ No Security Port security is disabled and all network traffic is forwarded through the port without any restrictions. ■ Continuous Learning MAC addresses are learned continuously by the port until the number of authorized addresses specified is reached. When this number is exceeded the first address that was learned by the port is deleted, allowing a new address to be learned. ■ Automatic Learning MAC addresses are learned continuously by the port until the number of authorized addresses specified is reached. When this number is exceeded the port automatically stops learning addresses and Disconnect Unauthorized Device (DUD) is enabled on the port. For further information see "What is Disconnect Unauthorized Device (DUD)?" on page 85. ■ Learning Off Only traffic received from an authorized address (either configured by management or learned while the port was prevously operating in the "Automatic Learning" mode) is forwarded. While in this mode the DUD operation is enabled. When a port in this mode has learned the maximum number of authorized addresses configured for the port then it will transition to the "Learning Off" mode. ■ Network Login When a 802.1X client has been successfully authorized, all network traffic is forwarded through the port without any restrictions. For further information see "What is Network Login?" on page 80. ■ Network Login (Secure) When a 802.1X client has been successfully authorized, only network traffic that is received from the authorized client device is forwarded through the port. The source MAC address in received packets is used to determine this; all traffic from other network devices is filtered. Disconnect Unauthorized Device (DUD) is enabled on the port.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122

78
C
HAPTER
10: M
AKING
Y
OUR
N
ETWORK
S
ECURE
Port Security
The Switch supports the following port security modes, which you can set
for an individual port or a range of ports:
No Security
Port security is disabled and all network traffic is forwarded through
the port without any restrictions.
Continuous Learning
MAC addresses are learned continuously by the port until the number
of authorized addresses specified is reached. When this number is
exceeded the first address that was learned by the port is deleted,
allowing a new address to be learned.
Automatic Learning
MAC addresses are learned continuously by the port until the number
of authorized addresses specified is reached. When this number is
exceeded the port automatically stops learning addresses and
Disconnect Unauthorized Device (DUD) is enabled on the port. For
further information see
“What is Disconnect Unauthorized Device
(DUD)?”
on
page 85
.
Learning Off
Only traffic received from an authorized address (either configured by
management or learned while the port was prevously operating in the
"Automatic Learning" mode) is forwarded. While in this mode the
DUD operation is enabled. When a port in this mode has learned the
maximum number of authorized addresses configured for the port
then it will transition to the "Learning Off" mode.
Network Login
When a 802.1X client has been successfully authorized, all network
traffic is forwarded through the port without any restrictions. For
further information see
“What is Network Login?”
on
page 80
.
Network Login (Secure)
When a 802.1X client has been successfully authorized, only network
traffic that is received from the authorized client device is forwarded
through the port. The source MAC address in received packets is used
to determine this; all traffic from other network devices is filtered.
Disconnect Unauthorized Device (DUD) is enabled on the port.