Configuring and Monitoring Port Security

Port Security

Syntax: port-security (Continued)

Addresses learned this way appear in the switch and port address tables and age out according to the MAC Age Interval in the System Information configuration screen of the Menu interface or the show system information listing. You can set the MAC age out time using the CLI, SNMP, Web, or menu interfaces. For more on the mac-age-timecommand, refer to the chapter titled “Interface Access and System Information” in the Management and Configuration Guide for your switch. To set the learn-mode to limited use this command syntax:

port-security <port-list> learn-mode limited address-limit < 1..32 > action < none send-alarm send-disable >

The default address-limit is 1 but may be set for each port to learn up to 32 addresses. The default action is none. To see the list of learned addresses for a port use the command:

show mac < port-list>

address-limit < integer >

When learn-mode is set to static, configured, or limited- continuous, the address-limit parameter specifies how many authorized devices (MAC addresses) to allow. Range: 1 (the default) to 8 for static and configured modes. For learn-mode with the limited-continuous option, the range is 1-32 addresses.

—Continued—

13-15