Configuring and Monitoring Port Security

Port Security Command Options and Operation

Syntax: port-security [e] < port-list> (- Continued -)

action < none send-alarm send-disable >

Specifies whether an SNMP trap is sent to a network management station. Operates when:

Learn mode is set to learn-mode static (static-learn) or learn-mode configured (static-configured) and the port detects an unauthorized device.

Learn mode is set to learn-mode continuous and there is a MAC address change on a port.

none (the default): Prevents an SNMP trap from being sent.

send alarm: Causes the switch to send an SNMP trap to a network management station.

send-disable: Available only with learn-mode configured and learn-mode static. Causes the switch to send an SNMP trap to a network management station and disable the port. If you subsequently re-enable the port without clearing the port’s intrusion flag, the port will block further intruders, but the switch will not disable the port again until you reset the intrusion flag. See the Note on page 9-19.

For information on configuring the switch for SNMP management, refer to the Management and Configuration Guide for your switch.

clear-intrusion-flag

Clears the intrusion flag for a specific port. (Refer to “Reading Intrusion Alerts and Resetting Alert Flags” on page 9-17.)

9-9