HP 6125G HP 6125G & 6125G/XG Blade Switches Security Command Reference - Page 146

port-security port-mode

Page 146 highlights

system-view [Sysname] port-security oui 000d-2a10-0033 index 4 port-security port-mode Syntax port-security port-mode { autolearn | mac-authentication | mac-else-userlogin-secure | mac-else-userlogin-secure-ext | secure | userlogin | userlogin-secure | userlogin-secure-ext | userlogin-secure-or-mac | userlogin-secure-or-mac-ext | userlogin-withoui } View undo port-security port-mode Layer 2 Ethernet interface view Default level 2: System level Parameters Keyword Security mode Description autolearn autoLearn In this mode, a port can learn MAC addresses, and allows frames sourced from learned or configured the MAC addresses to pass. The dynamically learned MAC addresses are secure MAC addresses. You can also configure secure MAC addresses by using the port-security mac-address security command. A secure MAC address never ages out by default. In addition, you can configure MAC addresses manually by using the mac-address dynamic and mac-address static commands for a port in autoLearn mode. When the number of secure MAC addresses reaches the upper limit set by the port-security max-mac-count command, the port changes to secure mode. mac-authentication macAddressWithR adius In this mode, a port performs MAC authentication for users and services multiple users. mac-else-userlogin -secure mac-else-userlogin -secure-ext macAddressElseUs erLoginSecure macAddressElseUs erLoginSecureExt This mode is the combination of the macAddressWithRadius and userLoginSecure modes, with MAC authentication having a higher priority. • A port in this mode performs MAC authentication 30 seconds after receiving a non-802.1X frame.. • Upon receiving an 802.1X frame, the port performs MAC authentication and then, if MAC authentication fails, 802.1X authentication. Similar to the macAddressElseUserLoginSecure mode except that a port in this mode supports multiple 802.1X and MAC authentication users. secure secure In this mode, MAC address learning is disabled on the port and you can configure MAC addresses by using the mac-address static and mac-address dynamic commands. The port permits only frames sourced from secure MAC addresses and MAC addresses you manually configured by using the mac-address static and mac-address dynamic commands. 137

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291

137
<Sysname> system-view
[Sysname] port-security oui 000d-2a10-0033 index 4
port-security port-mode
Syntax
port-security port-mode
{
autolearn
|
mac-authentication
|
mac-else-userlogin-secure
|
mac-else-userlogin-secure-ext
|
secure
|
userlogin
|
userlogin-secure
|
userlogin-secure-ext
|
userlogin-secure-or-mac
|
userlogin-secure-or-mac-ext
|
userlogin-withoui
}
undo port-security port-mode
View
Layer 2 Ethernet interface view
Default level
2: System level
Parameters
Keyword
Security mode
Description
autolearn
autoLearn
In this mode, a port can learn MAC addresses, and allows frames
sourced from learned or configured the MAC addresses to pass.
The dynamically learned MAC addresses are secure MAC
addresses. You can also configure secure MAC addresses by
using the
port-security mac-address security
command. A secure
MAC address never ages out by default. In addition, you can
configure MAC addresses manually by using the
mac-address
dynamic
and
mac-address static
commands for a port in autoLearn
mode.
When the number of secure MAC addresses reaches the upper
limit set by the
port-security max-mac-count
command, the port
changes to secure mode.
mac-authentication
macAddressWithR
adius
In this mode, a port performs MAC authentication for users and
services multiple users.
mac-else-userlogin
-secure
macAddressElseUs
erLoginSecure
This mode is the combination of the macAddressWithRadius and
userLoginSecure modes, with MAC authentication having a higher
priority.
A port in this mode
p
erforms MAC authentication 30 seconds
after receiving a non-802.1X frame..
Upon receiving an 802.1X frame, the port performs MAC
authentication and then, if MAC authentication fails, 802.1X
authentication.
mac-else-userlogin
-secure-ext
macAddressElseUs
erLoginSecureExt
Similar to the macAddressElseUserLoginSecure mode except that a
port in this mode supports multiple 802.1X and MAC
authentication users.
secure
secure
In this mode, MAC address learning is disabled on the port and
you can configure MAC addresses by using the
mac-address static
and
mac-address dynamic
commands.
The port permits only frames sourced from secure MAC addresses
and MAC addresses you manually configured by using the
mac-address static
and
mac-address dynamic
commands.