Qtech QSW-8200-52T-AC — настройка безопасности портов: команды и примеры использования [81/85]

Превью страниц Страница 81 / 85
Qtech QSW-8200-52F-AC-DC [81/85] Switchport port security violation
User Manual
Chapter 11. Commands for PORT SECURITY 81
www.qtech.ru
Parameter: valueConfigure the maximum number of the secure MAC allowed by the
interface, its range between 1 and 128. It is determined by the maximum MAC number
of the device.
vlan-id: Configure the maximum value for the specified VLAN, it only
takes effect on trunk and hybrid interfaces.
Default: After enabling port-security, if there is no other configuration, the maximum
number of the secure MAC is 1 on the interface. The interface number in VLAN is no
limit by default
Command Mode: Port mode
Usage Guide: Pay attention to the coupling relation about the number between the
interface and VLAN, set the maximum number configured by the interface as the
standard firstly.
Example: Configure the maximum number of the secure MAC on the interface.
Switch(config-if- ethernet1/0/1)# switchport port-security maximum 100
11.8 switchport port-security violation
Command: switchport port-security violation {protect | restrict | shutdown}
no switchport port-security violation
Function: When exceeding the maximum number of the configured MAC addresses,
MAC address accessing the interface does not belongs to this interface in MAC address
table or a MAC address is configured to several interfaces in same VLAN, both of them
will violate the security of the MAC address.
Parameter: protectProtect mode, it will trigger the action that do not learn the new
MAC, drop the package and do not send the warning.
restrictRestrict mode, it will trigger the action that do not learn the
new MAC, drop the package, send snmp trap and record the
configuration in syslog.
shutdownShutdown mode is the default mode. Under this condition,
the interface is disabled directly, send snmp trap and record the
configuration in syslog.
Default: Shutdown.
Command Mode: Port mode
Usage Guide: None.
Example: Configure violation mode as protect for the interface.
Switch(config-if-ethernet1/0/1)#switchport port-security violation protect

Содержание

145

Узнайте, как настроить безопасность портов с помощью команд для управления MAC-адресами. Примеры настройки и режимы нарушения безопасности помогут вам защитить сеть.