Netgear GS752TP GS728TP/GS728TPP/GS752TP Software Administration Manual - Page 184

Port Security Interface Configuration, Unknown Unicast, Multicast & Broadcast

Page 184 highlights

GS752TP, GS728TP, and GS728TPP Gigabit Smart Switches 2. Select the check box next to the port to configure. Select multiple check boxes to apply the same setting to all selected ports. Select the check box in the heading row to apply the same settings to all ports. 3. From the Status menu, select Enable or Disable to specify the administrative status of the mode. 4. From the Control Mode menu, select the mode of broadcast affected by storm control. • Broadcast Only. If the rate of L2 broadcast traffic ingressing on an interface increases beyond the configured threshold, the traffic is dropped. • Multicast & Broadcast. If the rate of L2 multicast and broadcast traffic ingressing on an interface increases beyond the configured threshold, the traffic is dropped. • Unknown Unicast, Multicast & Broadcast. If the rate of unknown L2 unicast (destination lookup failure), broadcast and multicast traffic ingressing on an interface increases beyond the configured threshold, the traffic is dropped. 5. In the Threshold field, specify the maximum rate at which unknown packets are forwarded. The range is a percentage of the total threshold between 0-100%. The default is 5%. Storm control is configured as a percentage of the maximum port speed. 6. Click APPLY to update the switch with the new settings. Port Security Interface Configuration A MAC address can be dynamically defined as allowable. Dynamic locking implements a first arrival mechanism for port security. You specify how many addresses can be learned on the locked port. If the limit has not been reached, a packet with an unknown source MAC address is learned and forwarded normally. When the limit is reached, no more addresses are learned on the port. Any packets with source MAC addresses that were not already learned are discarded. You can effectively disable dynamic locking by setting the number of allowable dynamic entries to 0.  To configure port security settings: 1. Select Security  Traffic Control > Port Security  Interface Configuration. Managing Device Security 184

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275

Managing Device Security
184
GS752TP, GS728TP, and GS728TPP Gigabit Smart Switches
2.
Select the check box next to the port to configure.
Select multiple check boxes to apply the same setting to all selected ports. Select the
check box in the heading row to apply the same settings to all ports.
3.
From the Status menu, select Enable or Disable to specify the administrative status of the
mode.
4.
From the Control Mode menu, select the mode of broadcast affected by storm control.
Broadcast Only
. If the rate of L2 broadcast traffic ingressing on an interface
increases beyond the configured threshold, the traffic is dropped.
Multicast & Broadcast
. If the rate of L2 multicast and broadcast traffic ingressing on
an interface increases beyond the configured threshold, the traffic is dropped.
Unknown Unicast, Multicast & Broadcast
. If the rate of unknown L2 unicast
(destination lookup failure), broadcast and multicast traffic ingressing on an interface
increases beyond the configured threshold, the traffic is dropped.
5.
In the Threshold field, specify the maximum rate at which unknown packets are forwarded.
The range is a percentage of the total threshold between 0–100%. The default is 5%.
Storm control is configured as a percentage of the maximum port speed.
6.
Click
APPLY
to update the switch with the new settings.
Port Security Interface Configuration
A MAC address can be dynamically defined as allowable.
Dynamic locking implements a first arrival mechanism for port security. You specify how
many addresses can be learned on the locked port. If the limit has not been reached, a
packet with an unknown source MAC address is learned and forwarded normally. When the
limit is reached, no more addresses are learned on the port. Any packets with source MAC
addresses that were not already learned are discarded. You can effectively disable dynamic
locking by setting the number of allowable dynamic entries to 0.
To configure port security settings:
1.
Select
Security
Traffic Control
>
Port Security
Interface Configuration
.