HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 100

Setting port security's limit on the number of secure MAC addresses on a port, Setting the port

Page 100 highlights

You can use the undo port-security enable command to disable port security. Because it logs off the online users, make sure no online users are present. Enabling or disabling port security resets the following security settings to the default: • 802.1X access control mode is MAC-based, and the port authorization state is auto. • Port security mode is noRestriction. For more information about 802.1X authentication and MAC authentication configuration, see "Configuring 802.1X" and "Configuring MAC authentication." Setting port security's limit on the number of secure MAC addresses on a port You can set the maximum number of secure MAC addresses that port security allows on a port for the following purposes: • Controlling the number of concurrent users on the port. For a port operating in a security mode that performs MAC authentication, 802.1X authentication, or both, the maximum number of concurrent users on the port equals this limit or the limit of the authentication mode in use, whichever is smaller. • Controlling the number of secure MAC addresses on the port in autoLearn mode. The port security's limit on the number of secure MAC addresses on a port is independent of the MAC learning limit described in MAC address table configuration in Layer 2-LAN Switching Configuration Guide. To set the maximum number of secure MAC addresses allowed on a port: Step 1. Enter system view. 2. Enter interface view. 3. Set the maximum number of secure MAC addresses allowed on a port. Command system-view interface interface-type interface-number port-security max-mac-count count-value Remarks N/A N/A By default, port security does not limit the number of secure MAC addresses on a port. Setting the port security mode Before you set a port security mode for a port, complete the following tasks: • Disable 802.1X and MAC authentication. • Verify that the port does not belong to any aggregation group or service loopback group. • If you are configuring the autoLearn mode, set port security's limit on the number of secure MAC addresses. You cannot change the setting when the port is operating in autoLearn mode. Follow these guidelines when you set the port security mode: • You can specify a port security mode when port security is disabled, but your configuration cannot take effect. • Changing the port security mode of a port logs off the online users of the port. 91

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

91
You can use the
undo port-security enable
command to disable port security. Because it logs off the
online users, make sure no online users are present.
Enabling or disabling port security resets the following security settings to the default:
802.1X access control mode is MAC-based, and the port authorization state is auto.
Port security mode is noRestriction.
For more information about 802.1X authentication and MAC authentication configuration, see
"
Configuring 802.1X
" and "
Configuring MAC authentication
."
Setting port security's limit on the number of secure
MAC addresses on a port
You can set the maximum number of secure MAC addresses that port security allows on a port for the
following purposes:
Controlling the number of concurrent users on the port. For a port operating in a security mode that
performs MAC authentication, 802.1X authentication, or both, the maximum number of concurrent
users on the port equals this limit or the limit of the authentication mode in use, whichever is smaller.
Controlling the number of secure MAC addresses on the port in autoLearn mode.
The port security's limit on the number of secure MAC addresses on a port is independent of the MAC
learning limit described in MAC address table configuration
in
Layer 2—LAN Switching Configuration
Guide
.
To set the maximum number of secure MAC addresses allowed on a port:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter interface view.
interface
interface-type
interface-number
N/A
3.
Set the maximum number of
secure MAC addresses
allowed on a port.
port-security max-mac-count
count-value
By default, port security does not
limit the number of secure MAC
addresses on a port.
Setting the port security mode
Before you set a port security mode for a port, complete the following tasks:
Disable 802.1X and MAC authentication.
Verify that the port does not belong to any aggregation group or service loopback group.
If you are configuring the autoLearn mode, set port security's limit on the number of secure MAC
addresses. You cannot change the setting when the port is operating in autoLearn mode.
Follow these guidelines when you set the port security mode:
You can specify a port security mode when port security is disabled, but your configuration cannot
take effect.
Changing the port security mode of a port logs off the online users of the port.