HP 6125G HP 6125G & 6125G/XG Blade Switches Security Command Reference - Page 134

Field, Description, Stored MAC address

Page 134 highlights

Field RALM logfailure trap AutoLearn aging time Disableport Timeout OUI value Port mode NeedToKnow mode Intrusion mode Max MAC address number Stored MAC address number Authorization Security MAC address learning mode Description Whether trapping for MAC authentication failure is enabled or not. If it is enabled, the port sends trap information when a user fails MAC address authentication. Secure MAC aging timer. The timer applies to sticky or dynamic secure MAC addresses. Silence timeout period of the port that receives illegal packets, in seconds. List of OUI values allowed Port security mode: • noRestrictions • autoLearn • macAddressWithRadius • macAddressElseUserLoginSecure • macAddressElseUserLoginSecureExt • secure • userLogin • userLoginSecure • userLoginSecureExt • macAddressOrUserLoginSecure • macAddressOrUserLoginSecureExt • userLoginWithOUI Need to know (NTK) mode: • NeedToKnowOnly-Allows only unicast packets with authenticated destination MAC addresses. • NeedToKnowWithBroadcast-Allows only unicast packets and broadcasts with authenticated destination MAC addresses. • NeedToKnowWithMulticast-Allows unicast packets, multicasts and broadcasts with authenticated destination MAC addresses. Intrusion protection action mode: • BlockMacAddress-Adds the source MAC address of the illegal packet to the blocked MAC address list. • DisablePort-Shuts down the port that receives illegal packets permanently. • DisablePortTemporarily-Shuts down the port that receives illegal packets for some time. • NoAction-Performs no intrusion protection. Maximum number of MAC addresses that port security allows on the port. Number of MAC addresses stored Whether the authorization information from the server is ignored or not: • permitted-Authorization information from the RADIUS server takes effect. • ignored-Authorization information from the RADIUS server does not take effect. Secure MAC address learning mode: • sticky-Learns MAC addresses as sticky secure MAC addresses. • dynamic-Learns MAC addresses as dynamic secure MAC addresses. 125

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291

125
Field
Description
RALM logfailure trap
Whether trapping for MAC authentication failure is enabled or not. If it is
enabled, the port sends trap information when a user fails MAC address
authentication.
AutoLearn aging time
Secure MAC aging timer. The timer applies to sticky or dynamic secure MAC
addresses.
Disableport Timeout
Silence timeout period of the port that receives illegal packets, in seconds.
OUI value
List of OUI values allowed
Port mode
Port security mode:
noRestrictions
autoLearn
macAddressWithRadius
macAddressElseUserLoginSecure
macAddressElseUserLoginSecureExt
secure
userLogin
userLoginSecure
userLoginSecureExt
macAddressOrUserLoginSecure
macAddressOrUserLoginSecureExt
userLoginWithOUI
NeedToKnow mode
Need to know (NTK) mode:
NeedToKnowOnly
—Allows only unicast packets with authenticated
destination MAC addresses.
NeedToKnowWithBroadcast
—Allows only unicast packets and broadcasts
with authenticated destination MAC addresses.
NeedToKnowWithMulticast
—Allows unicast packets, multicasts and
broadcasts with authenticated destination MAC addresses.
Intrusion mode
Intrusion protection action mode:
BlockMacAddress
—Adds the source MAC address of the illegal packet to
the blocked MAC address list.
DisablePort
—Shuts down the port that receives illegal packets permanently.
DisablePortTemporarily
—Shuts down the port that receives illegal packets
for some time.
NoAction
—Performs no intrusion protection.
Max MAC address number
Maximum number of MAC addresses that port security allows on the port.
Stored MAC address
number
Number of MAC addresses stored
Authorization
Whether the authorization information from the server is ignored or not:
permitted
—Authorization information from the RADIUS server takes effect.
ignored
—Authorization information from the RADIUS server does not take
effect.
Security MAC address
learning mode
Secure MAC address learning mode:
sticky
—Learns MAC addresses as sticky secure MAC addresses.
dynamic
—Learns MAC addresses as dynamic secure MAC addresses.