N o t e

Configuring and Monitoring Port Security

Overview

Overview

Feature

Default

Menu

CLI

Web

 

 

 

 

 

Displaying Current Port Security

n/a

page 13-8

page 13-33

Configuring Port Security

disabled

page 13-12

page 13-33

Retention of Static Addresses

n/a

page 13-17

n/a

MAC Lockdown

disabled

page 13-22

 

MAC Lockout

disabled

page 13-30

 

Intrusion Alerts and Alert Flags

n/a

page 13-39

page 13-37

page 13-40

 

 

 

 

 

Port Security (Page 13-4).This feature enables you to configure each switch port with a unique list of the MAC addresses of devices that are authorized to access the network through that port. This enables individual ports to detect, prevent, and log attempts by unauthorized devices to commu­ nicate through the switch.

This feature does not prevent intruders from receiving broadcast and multi­ cast traffic. Also, Port Security and MAC Lockdown are mutually exclusive on a switch. If one is enabled, then the other cannot be used.

MAC Lockdown (Page 13-22).This feature, also known as “Static Addressing”, is used to prevent station movement and MAC address “hijack­ ing” by allowing a given MAC address to use only an assigned port on the switch. MAC Lockdown also restricts the client device to a specific VLAN. (See also the Note, above.)

MAC Lockout (Page 13-30).This feature enables you to block a specific MAC address so that the switch drops all traffic to or from the specified address.

13-3