HP 6125G HP 6125G & 6125G/XG Blade Switches Security Command Reference - Page 141

port-security mac-address dynamic

Page 141 highlights

Description Use port-security mac-address aging-type inactivity to enable inactivity aging for secure MAC addresses (sticky or dynamic). Use undo port-security mac-address aging-type inactivity to restore the default. By default, the inactivity aging function is disabled. If only an aging timer is configured, the aging timer counts up regardless of whether traffic data has been sent from the sticky MAC address. When you use an aging timer together with the inactivity aging function, the aging timer restarts once traffic data is detected from the sticky MAC address. The inactivity aging function prevents the unauthorized use of a secure MAC address when the authorized user is offline, and removes outdated secure MAC addresses so new secure MAC addresses can be learned. Related commands: port-security timer autolearn aging, and port-security mac-address dynamic. Examples # Enable inactivity aging for secure MAC addresses on interface GigabitEthernet 1/0/1. system-view [Sysname] interface gigabitethernet 1/0/1 [Sysname-GigabitEthernet1/0/1] port-security mac-address aging-type inactivity port-security mac-address dynamic Syntax port-security mac-address dynamic undo port-security mac-address dynamic View Layer 2 Ethernet interface view Default level 2: System level Parameters None Description Use port-security mac-address dynamic to enable the dynamic secure MAC function. This function converts sticky MAC addresses to dynamic, and disables saving them to the configuration file. Use undo port-security mac-address dynamic to restore the default. By default, sticky MAC addresses can be saved to the configuration file, and once saved, survive a device reboot. After you execute the port-security mac-address dynamic command on a port, you cannot manually configure sticky MAC address, and secure MAC addresses automatically learned by the port in autoLearn mode are also dynamic. All dynamic MAC addresses are lost at reboot. Use this command when you want to clear all sticky MAC addresses after a device reboot. After you execute the undo port-security mac-address dynamic command on a port, all dynamic secure MAC addresses on the port are converted to sticky MAC addresses, and you can manually configure sticky MAC address. 132

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291

132
Description
Use
port-security mac-address aging-type inactivity
to enable inactivity aging for secure MAC
addresses (sticky or dynamic).
Use
undo port-security mac-address aging-type inactivity
to restore the default.
By default, the inactivity aging function is disabled.
If only an aging timer is configured, the aging timer counts up regardless of whether traffic data has been
sent from the sticky MAC address. When you use an aging timer together with the inactivity aging
function, the aging timer restarts once traffic data is detected from the sticky MAC address. The inactivity
aging function prevents the unauthorized use of a secure MAC address when the authorized user is
offline, and removes outdated secure MAC addresses so new secure MAC addresses can be learned.
Related commands:
port-security timer autolearn aging
, and
port-security mac-address dynamic
.
Examples
# Enable inactivity aging for secure MAC addresses on interface GigabitEthernet 1/0/1.
<Sysname> system-view
[Sysname] interface gigabitethernet 1/0/1
[Sysname-GigabitEthernet1/0/1] port-security mac-address aging-type inactivity
port-security mac-address dynamic
Syntax
port-security mac-address dynamic
undo port-security mac-address dynamic
View
Layer 2 Ethernet interface view
Default level
2: System level
Parameters
None
Description
Use
port-security mac-address dynamic
to enable the dynamic secure MAC function. This function
converts sticky MAC addresses to dynamic, and disables saving them to the configuration file.
Use
undo port-security mac-address dynamic
to restore the default.
By default, sticky MAC addresses can be saved to the configuration file, and once saved, survive a
device reboot.
After you execute the
port-security mac-address dynamic
command on a port, you cannot manually
configure sticky MAC address, and secure MAC addresses automatically learned by the port in
autoLearn mode are also dynamic. All dynamic MAC addresses are lost at reboot. Use this command
when you want to clear all sticky MAC addresses after a device reboot.
After you execute the
undo port-security mac-address dynamic
command on a port, all dynamic secure
MAC addresses on the port are converted to sticky MAC addresses, and you can manually configure
sticky MAC address.