D-Link DWS-4026 [368/741] Section 8 managing device security

D-Link DWS-4026 [368/741] Section 8 managing device security
ManagingDeviceSecurity
D-Link UnifiedWiredandWirelessAccessSystem
November2011 Page368
DLinkUWSUserManual
Section8:ManagingDeviceSecurity
UsethefeaturesintheSecurityfolderonthenavigationtreemenutosetmanagementsecurityparameters
forport,user,andserversecurity.
TheSecurityfoldercontainslinkstothefollowingfeatures:
“ConfiguringPortSecurity
“SSL/SecureHTTPConfiguration”
“SecureShell(SSH)Configuration”
“ConfiguringPortSecurity
“RADIUSSettings”
“PortAccessControl”
“TACACS+Settings”
ConfiguringPortSecurity
PortSecuritycanbeenabledonaperportbasis.Whenaportislocked,onlypacketswithallowablesource
MACaddressescanbeforwarded.Allotherpacketsarediscarded.AMACaddresscanbedefinedasallowable
byoneoftwomethods:dynamicallyorstatically.Notethatbothmethodsareuse
dconcurrentlywhenaport
islocked.
Dynamiclockingimplementsa“firstarrival”mechanismforPortSecurity.Youspecifyhowmanyaddressescan
belearnedonthelockedport.Ifthelimithasnotbeenreached,thenapacketwithanunknownsourceMAC
addressislearnedandforwardednormally. Oncetheli
mitisreached,nomoreaddressesarelearnedonthe
port.AnypacketswithsourceMACaddressesthatwerenotalreadylearnedarediscarded.Notethatyoucan
effectivelydisabledynamiclockingbysettingthenumberofallowabledynamicentriestozero.
StaticlockingallowsyoutospecifyalistofMA
Caddressesthatareallowedonaport.Thebehaviorofpackets
isthesameasfordynamiclocking:onlypacketswithanallowablesourceMACaddresscanbeforwarded.
ToseetheMACaddresseslearnedonaspecificport,see“ConfiguringandSearchingtheForwardingDatabase
onpage178.
Di
sabledportscanonlybeactivatedfromtheConfiguringPortspage.

Содержание

Похожие устройства

Скачать