Configuring and Monitoring Port Security

MAC Lockdown

Internal

Core

Network

There is no need to lock MAC addresses on switches in the internal core network.

3400cl or

5300xl Switch

3400cl or

5300xl Switch

Server “A”

3400cl or

5300xl Switch

3400cl or

5300xl Switch

Network Edge

2600 or

2600-PWR Switch

Lock Server “A” to

these ports.

2800 Switch

Edge Devices

Mixed Users

Figure 9-9. MAC Lockdown Deployed At the Network Edge Provides Security

Basic MAC Lockdown Deployment. In the Model Network Topology shown above, the switches that are connected to the edge of the network each have one and only one connection to the core network. This means each switch has only one path by which data can travel to Server A. You can use MAC Lockdown to specify that all traffic intended for Server A’s MAC Address must go through the one port on the edge switches. That way, users on the edge can still use other network resources, but they cannot “spoof” Server A and hijack data traffic which is intended for that server alone.

9-22

Page 252
Image 252
HP 4100gl, 2650 (J4899A/B), 2626 (J4900A/B), 2600-PWR, 6108 manual MAC Lockdown Deployed At the Network Edge Provides Security