АМАТЕК AN-SGM28P24-400 [70/322] Fourth chapters

АМАТЕК AN-SGM28P24-400 [70/322] Fourth chapters
69 / 322
Fourth chapters
Port based MAC security
This chapter introduces the port based MAC security configuration, including the following
contents
brief introduction
MAC binding configuration
MAC filter configuration
Port learning constraint configuration
4.1 brief introduction
Port based MAC security can provide three functions of MAC binding, MAC filtering and
port learning control to improve the security performance of the two layer forwarding of the
switch
MAC binding can be MAC and port together, limiting a specified MAC address can only be
in a specified port to access the network; the same time, the port can only allow these binding
MAC address to access the network; a port can simultaneously Bind multiple MAC addresses.
MAC binding can be applied to a designated port at the same time as 802.1xThis function is very
useful for some devices that do not have 802.1x functionality or are not convenient to use 802.1x
devices, such as printers, file servers, etc.
MAC filtering allows some designated MAC addresses to fail to access the network. The
main purpose is to prevent some illegal devices from accessing the networkWhen an MAC
address is configured as a MAC filter, the MAC address cannot be accessed at any port of the
switch in the network, also cannot receive the purpose of MAC is the specified MAC address data
packets, and MAC binding, a port can also configure multiple MAC MAC address filteringIn
application, if some virus software attacks the network through the forged MAC address, besides
ACL, the attack of controlling these forged packets can be accessed by MAC filtering
Port learning control can control a port to dynamically learn the number of MAC addresses.
If a port specifies that it can dynamically learn the number of MAC addresses, when the number
of MAC addresses learned by this port is equal to the number of the port configuration, the new
MAC address will no longer be learned. For these new MAC addresses The packet will be
discarded
It's important to note that the MAC address here is actually MAC+VID, and the description
behind this chapter is no longer necessaryIn addition, MAC binding function and 802.1x can be
configured on one port at the same time. MAC filtering and port learning limit can be configured
on one port at the same time. MAC binding function, 802.1x and MAC filtering, port learning
limit between the two groups can not be simultaneously Configured to the same port

Содержание

Похожие устройства

Скачать
Случайные обсуждения