To do…

 

Use the command…

 

Remarks

 

 

 

Enter Ethernet port view

 

interface interface-type

 

 

 

 

 

interface-number

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

port-security port-mode

 

 

 

 

 

 

 

{ autolearn

 

 

 

 

 

 

 

mac-and-userlogin-secure

Required

 

 

 

 

 

mac-and-userlogin-secure-e

 

 

 

 

 

 

 

 

 

 

 

 

xt mac-authentication

By default, a port operates in

 

 

 

 

mac-else-userlogin-secure

noRestriction mode. In this

 

 

 

Set the port security mode

mac-else-userlogin-secure-e

mode, access to the port is not

 

 

 

 

xt secure userlogin

restricted.

 

 

 

 

userlogin-secure

You can set a port security

 

 

 

 

userlogin-secure-ext

 

 

 

 

mode as needed.

 

 

 

 

userlogin-secure-or-mac

 

 

 

 

 

 

 

 

 

 

userlogin-secure-or-mac-ext

 

 

 

 

 

 

userlogin-withoui }

 

 

 

 

 

 

 

 

 

 

 

z

z

z

Before setting the port security mode to autolearn, you need to set the maximum number of MAC addresses allowed on the port with the port-securitymax-mac-countcommand.

After you set the port security mode to autolearn, you cannot configure any static or blackhole MAC addresses on the port.

If the port is in a security mode other than noRestriction, before you can change the port security mode, you need to restore the port security mode to noRestriction with the undo port-securityport-modecommand.

If the port-securityport-modemode command has been executed on a port, none of the following can be configured on the same port:

z

z

z

Maximum number of MAC addresses that the port can learn Reflector port for port mirroring

Link aggregation

Configuring Port Security Features

Configuring the NTK feature

Follow these steps to configure the NTK feature:

To do…

Use the command…

Remarks

Enter system view

system-view

 

 

 

Enter Ethernet port view

interface interface-type

interface-number

 

 

 

 

 

 

port-security ntk-mode

Required

Configure the NTK feature

{ ntkonly

Be default, NTK is disabled on

ntk-withbroadcasts

a port, namely all frames are

 

 

ntk-withmulticasts }

allowed to be sent.

 

 

 

1-6

Page 143
Image 143
3Com WX3000 operation manual Configuring Port Security Features, Configuring the NTK feature