HP 6125G HP 6125G & 6125G/XG Blade Switches Security Configuration Gui - Page 129
Configuring intrusion protection, Enabling port security traps
View all HP 6125G manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 129 highlights
• ntk-withmulticasts-Forwards only broadcast frames, multicast frames, and unicast frames with authenticated destination MAC addresses. To configure the NTK feature: Step 1. Enter system view. 2. Enter Layer 2 Ethernet interface view. 3. Configure the NTK feature. Command system-view interface interface-type interface-number port-security ntk-mode { ntk-withbroadcasts | ntk-withmulticasts | ntkonly } Remarks N/A N/A By default, NTK is disabled on a port and all frames are allowed to be sent. Configuring intrusion protection Intrusion protection enables a device to take one of the following actions in response to illegal frames: • blockmac-Adds the source MAC addresses of illegal frames to the blocked MAC addresses list and discards the frames. All subsequent frames sourced from a blocked MAC address will be dropped. A blocked MAC address is restored to normal state after being blocked for three minutes. The interval is fixed and cannot be changed. • disableport-Disables the port until you bring it up manually. • disableport-temporarily-Disables the port for a specific period of time. The period can be configured with the port-security timer disableport command. On a port operating in either the macAddressElseUserLoginSecure mode or the macAddressElseUserLoginSecureExt mode, intrusion protection is triggered only after both MAC authentication and 802.1X authentication for the same frame fail. To configure the intrusion protection feature: Step Command 1. Enter system view. system-view 2. Enter Layer 2 Ethernet interface view. interface interface-type interface-number 3. Configure the intrusion protection feature. port-security intrusion-mode { blockmac | disableport | disableport-temporarily } 4. Return to system view. quit 5. Set the silence timeout period during which a port remains disabled. port-security timer disableport time-value Remarks N/A N/A By default, intrusion protection is disabled. N/A Optional. 20 seconds by default. Enabling port security traps You can configure the port security module to send traps for the following categories of events: • addresslearned-Learning of new MAC addresses. 119