HP 6125G HP 6125G & 6125G/XG Blade Switches Security Configuration Gui - Page 131

Configuration prerequisites, Address sources, Aging mechanism, Can be saved and, survive a device

Page 131 highlights

Type Address sources Aging mechanism Dynamic Converted from sticky MAC addresses or automatically learned after the dynamic secure MAC function is enabled. Same as sticky MAC addresses. Can be saved and survive a device reboot? No. All dynamic secure MAC addresses are lost at reboot. Configuration prerequisites • Enable port security. • Set port security's limit on the number of MAC addresses on the port. Perform this task before you enable autoLearn mode. • Set the port security mode to autoLearn. Configuration procedure To configure a secure MAC address: Step 1. Enter system view. 2. Set the secure MAC aging timer. 3. Configure a secure MAC address. 4. Enter Layer 2 Ethernet interface view. 5. Enable inactivity aging. Command Remarks system-view N/A port-security timer autolearn aging time-value • Approach 1 (in system view): port-security mac-address security [ sticky] mac-address interface interface-type interface-number vlan vlan-id • Approach 2 (in interface view): a. interface interface-type interface-number b. port-security mac-address security [ sticky] mac-address vlan vlan-id c. quit interface interface-type interface-number Optional. By default, secure MAC addresses do note age out, and you can remove them only by performing the undo port-security mac-address security command, changing the port security mode, or disabling the port security feature. Use either approach. No secure MAC address exists by default. N/A port-security mac-address aging-type inactivity Optional. By default, the inactivity aging function is disabled. 121

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285

121
Type
Address sources
Aging mechanism
Can be saved and
survive a device
reboot?
Dynamic
Converted from sticky
MAC addresses or
automatically learned
after the dynamic
secure MAC function
is enabled.
Same as sticky MAC addresses.
No.
All dynamic secure
MAC addresses are
lost at reboot.
Configuration prerequisites
Enable port security.
Set port security’s limit on the number of MAC addresses on the port. Perform this task before you
enable autoLearn mode.
Set the port security mode to autoLearn.
Configuration procedure
To configure a secure MAC address:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Set the secure MAC aging
timer.
port-security timer autolearn aging
time-value
Optional.
By default, secure MAC addresses
do note age out, and you can
remove them only by performing the
undo port-security mac-address
security
command, changing the
port security mode, or disabling the
port security feature.
3.
Configure a secure MAC
address.
Approach 1 (in system view):
port-security mac-address
security
[
sticky
]
mac-address
interface
interface-type
interface-number
vlan
vlan-id
Approach 2 (in interface view):
a.
interface
interface-type
interface-numbe
r
b.
port-security
mac-address
security
[
sticky
]
mac-address
vlan
vlan-id
c.
quit
Use either approach.
No secure MAC address exists by
default.
4.
Enter Layer 2 Ethernet
interface view.
interface
interface-type
interface-number
N/A
5.
Enable inactivity aging.
port-security mac-address
aging-type inactivity
Optional.
By default, the inactivity aging
function is disabled.