ip icmp burst-normal burst-max lockup, 269 ip mtu, 159

ip policy route-map,123

ip tcp burst-normal burst-max lockup, 270 ip use-acl-on-arp,112 mac-authentication apply-mac-auth-filter,239

mac-authentication auth-fail-action block-traffic,239 mac-authentication auth-fail-action restrict-vlan,251 mac-authentication auth-fail-vlan-id,238 mac-authentication auth-timeout-action failure, 251 mac-authentication auth-timeout-action success, 250 mac-authentication clear-mac-session,248 mac-authentication disable-aging,219, 249 mac-authentication disable-ingress-filtering,241 mac-authentication dos-protecti,246 mac-authentication enable, 237 mac-authentication enable-dynamic-vlan,240 mac-authentication max-accepted-session,252 mac-authentication move-back-to-old-vlan,242 mac-authentication no-override-restrict-vlan,240 mac-authentication source-guard-protection enable, 247

maximum, 204 per-vlan,110 port security, 203

rate-limit input fixed, 275 rate-limit output shaping, 276, 277 rate-limit output shaping ethernet, 277 restrict-vlan,238 secure-mac-address,205

set interface null0, 123 source-guard enable, 296, 297 use-radius-server,49 violation restrict, 206 violation shutdown, 207

IP source guard

configuration notes and feature limitations, 295 IPv6

ACL configuration notes, 128 ACL traffic filtering criteria, 128 configuring an ACL, 129 creating an ACL, 132

default and implicit ACL action, 131 protocol names and numbers, 128

IPv6 ACL

adding a comment to an entry, 138 applying to a trunk group, 138 command syntax descriptions, 134 configuring for ICMP, 133 configuring for TCP, 133 configuring for UDP, 133

deleting a comment from an entry, 139

displaying, 139

enabling on an interface, 137 permit deny, 133

router remark, 138 support for logging, 139

L

login attempts, specifying maximum number for Telnet access, 9

M

MAC address

configuring the maximum per port, 219 filters for EAP frames, 182

MAC addresses displaying, 223

displaying in a MAC-based VLAN, 226 MAC port security

autosaving to the startup configuration, 205 clearing restricted MAC addresses, 207 clearing statistics, 207

clearing violation statistics, 207 configuration, 203

configuration notes and feature limitations, 202 disabling the port, 207

displaying information, 208

displaying restricted MAC addresses on a port, 210 displaying secure MAC addresses, 208 displaying statistics, 209

enabling, 203

local and global resources, 202 overview, 202

setting the age timer, 204

setting the maximum number of addresses, 204 specifying secure MAC addresses, 205

MAC-based VLAN aging, 217

and port up or down events, 212 clearing information, 227 configuration, 215

configuring for a dynamic host, 220 configuring for a static host, 219 configuring using SNMP, 221 displaying information, 221 displaying logging, 227

dynamic configuration, 220 feature structure, 212

Brocade ICX 6650 Security Configuration Guide

307

53-1002601-01

 

Page 327
Image 327
Brocade Communications Systems 6650 manual