HP 6125XLG R2306-HP 6125XLG Blade Switch Security Command Reference - Page 130

Default, Views, Predefined user roles, Parameters, Keyword, Security mode, Description

Page 130 highlights

Default A port operates in noRestriction mode, where port security does not take effect. Views Interface view Predefined user roles network-admin Parameters Keyword autolearn mac-authentication mac-else-userlogin-secu re mac-else-userlogin-secu re-ext secure Security mode autoLearn macAddressWithRad ius macAddressElseUserL oginSecure macAddressElseUserL oginSecureExt secure Description A port in this mode can learn MAC addresses. The automatically learned MAC addresses are not added to the MAC address table as dynamic MAC address but to the secure MAC address table as secure MAC addresses. You can also configure secure MAC addresses by using the port-security mac-address security command. A port in autoLearn mode allows frames sourced from secure MAC addresses and MAC addresses configured by using the mac-address dynamic and mac-address static commands to pass. When the number of secure MAC addresses reaches the upper limit set by the port-security max-mac-count command, the port changes to secure mode. In this mode, a port performs MAC authentication for users and services multiple users. This mode is the combination of the macAddressWithRadius and userLoginSecure modes, with MAC authentication having a higher priority. It allows one 802.1X authentication user and multiple MAC authentication users to log in. • Upon receiving a non-802.1X frame, a port in this mode performs only MAC authentication. • Upon receiving an 802.1X frame, the port performs MAC authentication and then, if MAC authentication fails, 802.1X authentication. Same as the macAddressElseUserLoginSecure mode except that a port in this mode supports multiple 802.1X and MAC authentication users. In this mode, MAC address learning is disabled on the port and you can configure MAC addresses by using the mac-address static and mac-address dynamic commands. The port permits only frames sourced from secure MAC addresses and MAC addresses you manually configured by using the mac-address static and mac-address dynamic commands. 121

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321

121
Default
A port operates in noRestriction mode, where port security does not take effect.
Views
Interface view
Predefined user roles
network-admin
Parameters
Keyword
Security mode
Description
autolearn
autoLearn
A port in this mode can learn MAC addresses. The
automatically learned MAC addresses are not added to
the MAC address table as dynamic MAC address but to
the secure MAC address table as secure MAC addresses.
You can also configure secure MAC addresses by using
the
port-security mac-address security
command.
A port in autoLearn mode allows frames sourced from
secure MAC addresses and MAC addresses configured
by using the
mac-address dynamic
and
mac-address static
commands to pass.
When the number of secure MAC addresses reaches the
upper limit set by the
port-security max-mac-count
command, the port changes to secure mode.
mac-authentication
macAddressWithRad
ius
In this mode, a port performs MAC authentication for users
and services multiple users.
mac-else-userlogin-secu
re
macAddressElseUserL
oginSecure
This mode is the combination of the
macAddressWithRadius and userLoginSecure modes, with
MAC authentication having a higher priority. It allows one
802.1X authentication user and multiple MAC
authentication users to log in.
Upon receiving a non-802.1X frame, a port in this
mode performs only MAC authentication.
Upon receiving an 802.1X frame, the port performs
MAC authentication and then, if MAC authentication
fails, 802.1X authentication.
mac-else-userlogin-secu
re-ext
macAddressElseUserL
oginSecureExt
Same as the macAddressElseUserLoginSecure mode
except that a port in this mode supports multiple 802.1X
and MAC authentication users.
secure
secure
In this mode, MAC address learning is disabled on the
port and you can configure MAC addresses by using the
mac-address static
and
mac-address dynamic
commands.
The port permits only frames sourced from secure MAC
addresses and MAC addresses you manually configured
by using the
mac-address static
and
mac-address dynamic
commands.