Linksys SLM2024, SLM248P, SLM248G, SLM224P, SLM2048, SLM224G manual Security Port Security

Page 27

Chapter 4

Configuration Using the Web-based Utility

Security > Port Security

The Port Security screen is used to configure a port’s security settings.

Security > Ports Security

Network security can be increased by limiting access on a specific port only to users with specific MAC addresses. MAC addresses can be dynamically learned or statically configured.

Locked port security monitors both received and learned packets that are received on specific ports. Access to the locked port is limited to users with specific MAC addresses. These addresses are either manually defined on the port, or learned on that port up to the point when it is locked. When a packet is received on a locked port, and the packet’s source MAC address is not tied to that port (either it was learned on a different port, or it is unknown to the system), the protection mechanism is invoked, and can provide various options. Unauthorized packets arriving at a locked port are either:

Forwarded

Discarded

Cause the port to be shut down

Locked port security also enables storing a list of MAC addresses in the configuration file. The MAC address list can be restored after the device has been reset.

Disabled ports can be reactivated from the Port Settings screen of the Port Management tab.

Interface  Select Port or LAG, then select the desired interface from the appropriate drop-down menu.

Lock Interface  Select this option to lock the interface. The default is not selected (interface not locked).

Learning Mode  Defines the locked port type. This field is enabled only if Lock Interface is not selected. The possible values are:

Classic Lock  Locks the port using the classic lock mechanism. The port is immediately locked, regardless of how many addresses have already been learned.

Limited Dynamic Lock  Locks the port by deleting the current dynamic MAC addresses associated with the port. The port learns up to the maximum number of addresses allowed on the port. Both relearning and aging MAC addresses are enabled.

In order to change the Learning Mode, the Lock Interface must be unselected. Once the Learning Mode is changed, the Lock Interface can be reinstated.

Max Entries  Specifies the number of MAC addresses that can be learned on the port. This field is enabled only if Learning Mode is set to Limited Dynamic Lock. The default value is 1.

Action on Violation  Indicates the action to be applied to packets arriving on a locked port. The possible values are:

Discard  Discards packets from any unlearned source. This is the default value.

Forward  Forwards packets from an unknown source without learning the MAC address.

Shutdown  Discards packets from any unlearned source and shuts down the port. The port remains shut down until reactivated, or until the device is reset.

Update  If you click this button, your changes are saved and appear immediately in the table at the bottom of the Port Security screen.

The lower portion of the Port Security screen displays a summary of the settings in the upper portion of the screen. The settings are displayed for each of the ports on the Switch.

Click Save Settings to apply the changes, or Cancel Changes to cancel the changes.

Business Series Smart Gigabit Ethernet Switch

22

Image 27
Contents Business Series Smart Gigabit Ethernet Switch Online Resources About This GuideAbout This Guide Icon DescriptionsTable of Contents Table of Contents Appendix B Glossary Appendix C Specifications Appendix D Warranty and Regulatory InformationAppendix E Contact Information Introduction Chapter IntroductionBack Panel Chapter Product OverviewProduct Overview SLM2048SLM2024 SLM248G SLM248P SLM224G SLM224P Placement Options Chapter InstallationInstallation Pre-Installation ConsiderationsHardware Installation Desktop PlacementRack-Mount Placement With Uplinking the SwitchChapter Configuration Using Web-based Utility SetupSetup Summary Identification Setup Network SettingsDevice Information System InformationDaylight Saving Setup TimeIP Configuration Local TimePort Management Port Settings Port ConfigurationPort Management Port Management Link Aggregation LAG Configuration Port Priority Port Management PoE Power SettingsPort Management Lacp Global ParameterVlan Management Port to Vlan Vlan Management Port SettingsVlan Management Vlan Management Create VlanPort The number of the port being configured Vlan Management Vlan to PortJoin Vlan to Port Ethernet-like StatisticsStatistics Interface Statistics InterfaceParameters Security 802.1x SettingsSetting Timer SecuritySecurity Port Security Broadcast Only Counts only Broadcast traffic Security IP Access ListSecurity Storm Control IP Address Enter the IP address to be allowedSecurity Radius QoS QoS CoS SettingsCoS Settings CoS DefaultQoS Queue Settings QoS Dscp SettingsQoS Basic Mode Spanning Tree Global STP Global SettingSpanning Tree Spanning Tree STP StatusSpanning Tree STP Port Settings Bridge SettingsSpeed Displays the speed at which the port is operating Multicast Bridge Multicast Vlan Igmp SettingsMulticast Multicast Igmp SnoopingMulticast Bridge Multicast Forward All Local User Edit AdminAdmin User Authentication User AuthenticationSecure The entry is defined for locked ports Admin Static AddressAdmin Dynamic Address QueryAdmin Save Configuration Admin Port MirroringClick the Reboot button, then click OK to confirm Admin Firmware UpgradeAdmin Reboot Admin Factory DefaultAdmin Logging Admin Memory LogsAdmin Flash Logs If you select Yes, a confirmation screen appears LogoutAppendix a About Gigabit Ethernet Fiber Optic Cabling Gigabit EthernetFiber Optic Cabling Glossary Appendix B GlossaryGlossary Mail protocol on the Internet Packet a unit of data sent over a networkAppendix B Appendix C Specifications SpecificationsSLM2024/SLM2048 UL, cUL, CE mark, CB Power Internal Power CertificationConnectors for 10BASE-T Buttons Reset Cabling Type UTP CAT 5 or better for28 lb 3.3 kg Unit Weight39 lb 2.9 kg 83 lb 3.1 kgLimited Warranty Appendix D Warranty and Regulatory InformationRèglement d’Industry Canada Safety NoticesFCC Statement Industry Canada StatementDansk Danish Miljøinformation for kunder i EU Appendix D Norsk Norwegian Miljøinformasjon for kunder i EU Appendix D Contact Information Appendix E