Network Security
[ Network Security > Port Security ]
100
RM GUI GRS
Release
8.0
09/2019
4.2
Port Security
[ Network Security > Port Security ]
The device lets you transmit only data packets from desired senders on one port. When this
function is enabled, the device checks the VLAN ID and MAC address of the sender before it
transmits a data packet. The device discards data packets from other senders and logs this event.
If the
Auto-Disable
function is activated, the device disables the port. This restriction makes MAC
Spoofing attacks more difficult. The
Auto-Disable
function enables the relevant port again
automatically when the parameters are no longer being exceeded.
In this dialog a
Wizard
window helps you to connect the ports with one or more desired sources. In
the device these addresses are known as
Static entries (/)
. To view the specified static addresses,
highlight the relevant port and click the button.
To simplify the setup process, the device lets you record the desired senders automatically. The
device “learns” the senders by evaluating the received data packets. In the device these addresses
are known as
Dynamic entries
. When a user-defined upper limit has been reached (
Dynamic limit
), the
device stops the “learning” on the relevant port and transmits only the data packets of the senders
already recorded. When you adjust the upper limit to the number of expected senders, you thus
make MAC Flooding attacks more difficult.
Note:
With the automatic recording of the
Dynamic entries
, the device constantly discards the 1st
data packet from unknown senders. Using this 1st data packet, the device checks whether the
upper limit has been reached. The device records the sender until the upper limit is reached.
Afterwards, the device transmits data packets that it receives on the relevant port from this sender.
Operation
Operation
Enables/disables the
Port Security
function.
Possible values:
On
The
Port Security
function is enabled.
The device checks the VLAN ID and MAC address of the source before it transmits a data
packet.
The device transmits a received data packet only if its source is desired on the relevant port.
Also activate the checking of the source on the relevant ports.
Off
(default setting)
The
Port Security
function is disabled.
The device transmits every received data packet without checking the source.
Configuration
Auto-disable
Activates/deactivates the
Auto-Disable
function for
Port Security
.
Summary of Contents for GREYHOUND GRS1020
Page 8: ......
Page 16: ......
Page 146: ......
Page 232: ......
Page 310: ......
Page 330: ......
Page 338: ...Readers Comments 337 RM GUI GRS Release 8 0 09 2019 ...
Page 339: ......
Page 340: ......
Page 350: ......
Page 354: ......
Page 617: ...Readers Comments 277 UM Config GRS Release 8 0 09 2019 ...
Page 618: ......
Page 619: ......