HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 103

Configuring secure MAC addresses, Configuration prerequisites

Page 103 highlights

Configuring secure MAC addresses Secure MAC addresses are configured or learned in autoLearn mode. If they are saved, they can survive a device reboot. You can bind a secure MAC address to only one port in a VLAN. Secure MAC addresses include static and sticky secure MAC addresses. Table 5 A comparison of static and sticky secure MAC addresses Type Address sources Aging mechanism Can be saved and survive a device reboot? Static Manually added Not available. They never age out unless you manually remove Yes. them, change the port security mode, or disable the port security feature. Sticky Manually added or automatically learned by ports Sticky MAC addresses by default do not age out, but you can configure an aging timer to delete old sticky MAC addresses. If you set the aging timer to 0, sticky MAC addresses never age out. Yes. The aging timer restarts at a reboot. NOTE: When the maximum number of secure MAC address entries is reached, the port changes to secure mode, and it cannot add or learn any more secure MAC addresses. The port allows only frames sourced from a secure MAC address or a MAC address configured by using the mac-address dynamic or mac-address static command to pass through. Configuration prerequisites • Enable port security. • Set port security's limit on the number of MAC addresses on the port. Perform this task before you enable autoLearn mode. • Set the port security mode to autoLearn. • Configure the port to permit packets of the specified VLAN to pass or add the port to the VLAN. Make sure the VLAN already exists. Configuration procedure To configure a secure MAC address: Step 1. Enter system view. 2. (Optional.) Set the secure MAC aging timer. Command system-view port-security timer autolearn aging time-value Remarks N/A By default, secure MAC addresses do not age out. 94

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

94
Configuring secure MAC addresses
Secure MAC addresses are configured or learned in autoLearn mode. If they are saved, they can survive
a device reboot. You can bind a secure MAC address to only one port in a VLAN.
Secure MAC addresses include static and sticky secure MAC addresses.
Table 5
A comparison of static and sticky secure MAC addresses
Type
Address sources
Aging mechanism
Can be saved and
survive a device
reboot?
Static
Manually added
Not available.
They never age out unless you manually remove
them, change the port security mode, or disable
the port security feature.
Yes.
Sticky
Manually added or
automatically learned
by ports
Sticky MAC addresses by default do not age
out, but you can configure an aging timer to
delete old sticky MAC addresses. If you set the
aging timer to 0, sticky MAC addresses never
age out.
Yes.
The aging timer restarts
at a reboot.
NOTE:
When the maximum number of secure MAC address entries is reached, the port changes to secure mode, and
it cannot add or learn any more secure MAC addresses. The port allows only frames sourced from a secure
MAC address or a MAC address configured by using the
mac-address dynamic
or
mac-address static
command to pass through.
Configuration prerequisites
Enable port security.
Set port security's limit on the number of MAC addresses on the port. Perform this task before you
enable autoLearn mode.
Set the port security mode to autoLearn.
Configure the port to permit packets of the specified VLAN to pass or add the port to the VLAN.
Make sure the VLAN already exists.
Configuration procedure
To configure a secure MAC address:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
(Optional.) Set the
secure MAC aging
timer.
port-security timer autolearn aging
time-value
By default, secure MAC addresses
do not age out.