72 |
|
Table 9: Example output from the SHOW SWITCH PORT INTRUSION command.
Switch Port Information
Port 2 - 13 intrusion(s) detected
A switch port can be manually locked before it reaches the learning limit, by using the command:
ACTIVATE SWITCH
Addresses can be manually added to a port locked list up to a total of 256 MAC addresses, and the learning limit can be extended to accommodate them, by using the command:
ADD SWITCH FILTER ACTION={FORWARDDISCARD} DESTADDRESS=macadd
PORT=port [ENTRY=entry] [LEARN] [VLAN={vlanname1..4094}]
Learned addresses on locked ports can be saved as part of the switch configuration, so that they will be part of the configuration after a power cycle, using the command:
CREATE CONFIG=filename
If the configuration is not saved when there is a locked list for a port, the learning process begins again after the switch is restarted.
Virtual Local Area Networks (VLANs)
A Virtual LAN (VLAN) is a logical,
Decoupling logical broadcast domains from the physical wiring topology offers several advantages, including the ability to:
■Move devices and people with minimal, or no, reconfiguration
■Change a device’s broadcast domain and access to resources without physically moving the device, by software reconfiguration or by moving its cable from one switch port to another
■Isolate parts of the network from other parts, by placing them in different VLANs
■Share servers and other network resources without losing data isolation or security
■Direct broadcast traffic to only those devices which need to receive it, to reduce traffic across the network
■Connect
Software Release 2.6.1