Port Security Configuration Example
91
Port Security
Configuration
Example
Network requirements
■
Enable port security on port GigabitEthernet1/0/1 of switch A, and set the
maximum number of the MAC addresses accommodated by the port to 80.
■
The NTK packet transmission mode of on the port is
ntk-withbroadcasts
, and
the intrusion Protection mode is
disableport
.
■
Connect PC1 to GigabitEthernet1/0/1 through switch B.
■
Bind the MAC and IP addresses of PC1 to GigabitEthernet1/0/1.
Network diagram
Figure 28
Network diagram for port security configuration
Configuration procedure
Configure switch A as follows:
1
Enter system view.
<S4200G>
system-view
2
Enable port security.
[4200G]
port-security enable
3
Enter port view for GigabitEthernet1/0/1.
[4200G]
interface GigabitEthernet1/0/1
4
Set the port mode to MAC authentication.
[4200G-GigabitEthernet1/0/1]
port-security port-mode mac-authentication
5
Set the maximum number of MAC addresses accommodate by the port to 80.
[4200G-GigabitEthernet1/0/1]
port-security max-mac-count 80
6
Set the NTK packet transmission mode to
ntk-withbroadcasts
.
[4200G-GigabitEthernet1/0/1]
port-security ntk-mode ntk-withbroadcasts
7
Set the Intrusion Protection mode to
disableport
.
[4200G-GigabitEthernet1/0/1]
port-security intrusion-mode disableport
8
Return to system view.
[4200G-GigabitEthernet1/0/1]
quit
Display the information about port
binding
display am user-bind
[
interface
interface-type
interface-number
|
mac-addr
|
ip-addr ]
Table 68
Display port security (Continued)
Operation
Command
Switch A
Switch B
GE1/0/1
PC1
PC2
IP Address: 10.153.1.1
MAC Address: 00e0 -fc00 -3900
PC1
PC2
Switch A
Switch B
PC1
PC2
IP Address: 10.153.1.1
MAC Address: 00e0 -fc00 -3900
Switch A
Switch B
PC1
PC2
IP Address: 10.153.1.1
MAC Address: 00e0 -fc00 -3900
PC1
PC2
Summary of Contents for 4200G 12-Port
Page 10: ...8 CONTENTS...
Page 14: ...4 ABOUT THIS GUIDE...
Page 46: ...32 CHAPTER 5 LOGGING IN THROUGH WEB BASED NETWORK MANAGEMENT SYSTEM...
Page 48: ...34 CHAPTER 6 LOGGING IN THROUGH NMS...
Page 60: ...46 CHAPTER 9 VLAN CONFIGURATION...
Page 64: ...50 CHAPTER 10 MANAGEMENT VLAN CONFIGURATION...
Page 80: ...66 CHAPTER 13 GVRP CONFIGURATION...
Page 98: ...84 CHAPTER 15 LINK AGGREGATION CONFIGURATION...
Page 112: ...98 CHAPTER 18 MAC ADDRESS TABLE MANAGEMENT...
Page 126: ...112 CHAPTER 19 LOGGING IN THROUGH TELNET...
Page 162: ...148 CHAPTER 20 MSTP CONFIGURATION...
Page 274: ...260 CHAPTER 29 IGMP SNOOPING CONFIGURATION...
Page 276: ...262 CHAPTER 30 ROUTING PORT JOIN TO MULTICAST GROUP CONFIGURATION...
Page 298: ...284 CHAPTER 33 SNMP CONFIGURATION...
Page 304: ...290 CHAPTER 34 RMON CONFIGURATION...
Page 338: ...324 CHAPTER 36 SSH TERMINAL SERVICES...
Page 356: ...342 CHAPTER 38 FTP AND TFTP CONFIGURATION...
Page 365: ...Information Center Configuration Example 351 S4200G terminal logging...
Page 366: ...352 CHAPTER 39 INFORMATION CENTER...
Page 378: ...364 CHAPTER 40 BOOTROM AND HOST SOFTWARE LOADING...
Page 384: ...370 CHAPTER 41 Basic System Configuration and Debugging...
Page 388: ...374 CHAPTER 43 NETWORK CONNECTIVITY TEST...
Page 406: ...392 CHAPTER 45 CONFIGURATION OF NEWLY ADDED CLUSTER FUNCTIONS...