1-2
Table 1-1
Description of port security modes
Security mode
Description
Feature
noRestriction
In this mode, access to the port is not
restricted.
In this mode, neither the
NTK nor the intrusion
protection feature is
triggered.
autolearn
In this mode, a port can learn a specified
number of MAC addresses and save those
addresses as security MAC addresses. It
permits only packets whose source MAC
addresses are the security MAC addresses
that were learned or configured manually.
When the number of security MAC addresses
reaches the upper limit configured by the
port-security max-count
command, the port
changes to work in
secure
mode and no more
MAC addresses can be added to the port.
secure
In this mode, MAC address learning is
disabled on the port. The port permits packets
whose source MAC addresses are static and
dynamic MAC addresses that were configured
manually.
When the port mode changes from
autolearn
to
secure
, the security MAC addresses that
were learned in the
autolearn
mode are
permitted to pass through the port.
In either
mode, the device
will trigger NTK and
intrusion protection upon
detecting an illegal
packet.