Allied Telesis 86241-06 manual Dynamic Port Security

Page 29

Patch 86241-06 For Rapier Switches

29

Dynamic Port Security

Dynamic Port Security allows for dynamic MAC address learning on a switch port. If a MAC address is unused for a period of time, it will be aged from the database of currently accepted MAC addresses. This allows the learning of new MAC addresses, which is useful because port security allows the number of devices that are connected to a particular switch port to be limited.

MAC address learning can be set to static or dynamic by using the RELEARN parameter in the following command:

SET SWITCH PORT={port-listALL} [ACCEPTABLE={ALLVLAN}] [BCLIMIT={NONElimit}] [DESCRIPTION=description] [DLFLIMIT={NONElimit}] [EGRESSLIMIT={NONEDEFAULT01000..1270008..1016}] [INFILTERING={OFFON}] [INGRESSLIMIT={NONEDEFAULT064..1270008..1016}] [LEARN={NONE01..256]

[INTRUSIONACTION={DISABLEDISCARDTRAP}] [MCLIMIT={NONElimit}] [MIRROR={BOTHNONERXTX}] [MODE={AUTONEGOTIATEMASTERSLAVE}] [MULTICASTMODE={ABC}] [RELEARN={OFFON}] [SPEED={AUTONEGOTIATE10MHALF10MFULL10MHAUTO10MFAUTO 100MHALF100MFULL100MHAUTO100MFAUTO1000MHALF1000MF ULL1000MHAUTO1000MFAUTO}]

The RELEARN parameter determines whether dynamic or static MAC address learning will be used on this port. This parameter has no effect if the security feature limiting the number of MAC addresses is disabled (i.e. when LEARN=0 or NONE).

If the RELEARN parameter is set to OFF, static MAC address learning is used. Once a MAC address has been learned it will remain permanently in the learning database. IF the RELEARN parameter is set to ON, dynamic MAC address learning is used. If a MAC address is unused for a period of time, it will be removed from the learning database. Another (or the same) MAC address can then be learned and stored in the vacant position in the learning database. When RELEARN is enabled on a port, all existing entries in the learning database are removed. The elapsed time before a MAC address entry is removed can be set using the SET SWITCH AGEINGTIMER command (See the Switch Chapter for more information). The default is OFF.

To see whether the switch is using static or dynamic port security, use the command:

SHOW SWITCH PORT[={port-listALL}]

This command displays general information about the specified switch ports or all switch ports.

Patch 86241-05 for Software Release 2.4.1 C613-10340-00 REV E

Image 29
Contents Patch For Rapier Switches PCR Module SWI PCR Module IPG LevelPCR Module PIM Level PCR Module BGP LevelPCR 03064 Module Snmp Level PCR Module SSH LevelPCR Module SWI Level PCR Module Utility LevelPCR Module FR, PPP Level PCR 03100 Module Dhcp LevelPCR 03108 Module Mlds Level PCR 03113 Module Dvmrp LevelPCR Module DS3 Level PCR 03123 Module Dhcp LevelPCR Module IPV6 Level PCR Module Ospf LevelPCR Module DS3 Network affecting No PCR 02315 Module Snmp Network affecting NoPCR Module IPv6, SWI, IPG, Vlan Network affecting No PCR Module IPG, SWI, Vlan Network affecting NoPCR Module User Network affecting No PCR Module Install Network affecting NoPCR Module Utility Network affecting No PCR Module Firewall Network affecting NoPCR Module Network affecting No PCR Module IPG Network affecting NoPCR Module Ospf IPG Network affecting No PCR Module Ping Network affecting NoPCR Module TELNET, PING, IPV6, Network affecting No PCR 02523 Module QOS, Utility Network affecting NoPCR 02529 Module FIREWALLNetwork affecting No PCR 02532 Module FIREWALLNetwork affecting NoPCR Module Classifier Network affecting No PCR 02538 Module Dvmrp Network affecting NoPCR Module IPV6 Network affecting No PCR Module SWI Network affecting NoPCR 02579 Module FIREWALLNetwork affecting No PCR 02574 Module DVMRPNetwork affecting NoPCR 02587 Module OSPFNetwork affecting No PCR 02467 Module Core Network affecting NoPCR Module IPG, PIM, SWI Network affecting No PCR 02469 Module TMNetwork affecting NoPCR 02495 Module Vlan Network affecting No PCR 02498 Module Vlan Network affecting NoPCR 02509 Module DVMRPNetwork affecting No PCR 02502 Module Ping, IPv6Network affecting NoPCR Module DNS Relay Network affecting No PCR Module Vrrp Network affecting NoPCR Module Tpad Network affecting No PCR Module BGP Network affecting NoPCR 02277 Module Dvmrp Network affecting No PCR Module TELNET, TTY Network affecting NoPCR 02292 Module IPSECNetwork affecting No PCR 02303 Module INSTALLNetwork affecting NoPCR 02294 Module IKMPNetwork affecting No PCR 02301 Module IPGNetwork affecting NoPCR Module IPG/FIREWALL Network affecting No PCR Module FR Network affecting NoPCR Module IPG, ETH Network affecting No PCR Module Ipsec Network affecting NoPCR Module BGP, IPG Network affecting No PCR Module PPP Network affecting NoPCR 02348 Module Enco Network affecting No PCR Module SCC, SYN, PPP Network affecting NoPCR 02397 Module Dvmrp Network affecting No PCR Module FFS, FILE, TTY Network affecting NoPCR Module VRRP, TRG Network affecting No PCR Module SNMP, CORE, SHOW, Network affecting No PCR Module Trace Network affecting NoPCR Module STP Network affecting No PCR Module IPG Network affecting No Module VrrpPCR 02452 Module IPv6Network affecting No PCR 02450 Module IPV6Network affecting NoPCR 02457 Module IPV6Network affecting No PCR 02463 Module DVMRP, IPG Network affecting NoPCR Module Switch Network affecting No PCR Module DHCP, IPG Network affecting No DS3 InterfacesBit Parity Mode Loopbacks DS3 Configuration Patch Release Note Disable DS3 Debug Disable DS3 Test Enable DS3 Debug Create Framerelay Show Framerelay Dynamic Port Security Availability