MAC port security configuration

Brocade devices do not support the reserved-vlan-idnum command, which changes the default VLAN ID for the MAC port security feature.

The SNMP trap generated for restricted MAC addresses indicates the VLAN ID associated with the MAC address, as well as the port number and MAC address.

MAC port security is not supported on ports that have multi-device port authentication enabled.

The first packet from each new secure MAC address is dropped if secure MAC addresses are learned dynamically.

MAC port security configuration

To configure the MAC port security feature, perform the following tasks:

Enable the MAC port security feature

Set the maximum number of secure MAC addresses for an interface

Set the port security age timer

Specify secure MAC addresses

Configure the device to automatically save secure MAC addresses to the startup-config file

Specify the action taken when a security violation occurs

Enabling the MAC port security feature

By default, the MAC port security feature is disabled on all interfaces. You can enable or disable the feature on all interfaces at once, or on individual interfaces.

To enable the feature on all interfaces at once, enter the following commands.

Brocade(config)# port security

Brocade(config-port-security)# enable

To disable the feature on all interfaces at once, enter the following commands.

Brocade(config)# port security

Brocade(config-port-security)# no enable

To enable the feature on a specific interface, enter the following commands.

Brocade(config)# interface ethernet 1/1/7

Brocade(config-if-e10000-1/1/7)# port security

Brocade(config-port-security-e10000-1/1/7)# enable

Syntax: port security

Syntax: [no] enable

Brocade ICX 6650 Security Configuration Guide

203

53-1002601-01

 

Page 223
Image 223
Brocade Communications Systems 6650 manual MAC port security configuration, Enabling the MAC port security feature