SMC Networks SMC6624M manual Port Security Parameters, Ethernet port-list

Models: SMC6624M

1 364
Download 364 pages 24.74 Kb
Page 132
Image 132

Using Passwords, Port Security, and Authorized IP

Using Passwords, Port Security, and Authorized IP Managers To Protect Against Unauthorized Access

Configuring and Monitoring Port Security

Table 7-1. Port Security Parameters

Parameter

Description

 

 

 

 

Port List

<[ethernet] port-list>

Identifies the port or ports on which to apply a port security command.

 

 

 

Learn

learn-mode <static continuous>

Specifies how the port acquires authorized addresses.

Mode

Continuous (the Default): Appears in the factory-default setting or when you execute no port-security.Allows the port to learn addresses from inbound traffic from any device(s) to which it is connected. In this state, the port accepts traaffic from any device(s) to which it is connected. Addresses learned this way appear in the switch and port address tables and age out according to the Address Age Interval in the System Information configuration screen (page 5-21).

Static: Enables you to use the mac-addressparameter to specify the MAC addresses of the devices authorized for a port, and the address-limitparameter to specify the number of MAC addresses authorized for the port. You can authorize specific devices for the port, while still allowing the port to accept other, non-specified devices until the device limit has been reached. That is, if you enter fewer MAC addresses than you authorized, the port authorizes the remaining addresses in the order in which it automatically learns them. For example, If you use address-limitto specify three authorized devices, but use mac-addressto specify only one authorized MAC address, the port adds the one specifically authorized MAC address to its authorized-devices list and the first two additional MAC addresses it detects. For example, suppose:

You use mac-addressto authorize MAC address 0060b0-880a80 for port 4.

You use address-limitto allow three devices on port 4 and the port detects a series of MAC addresses in the following order:

080090-1362f2

00f031-423fc1

080071-0c45a1

0060b0-880a80

(the address you authorized with the mac-addressparameter)

In the above case, port four would assume the following list of authorized addresses:

080090-1362f2

(the first address the port detected)

00f031-423fc1

(the second address the port detected)

0060b0-880a80

(the address you authorized with the mac-addressparameter)

The remaining MAC address the port detects, 080071-0c45a1, is not allowed in the list of authorized addresses, and so is handled as an intruder.

Permanence of Authorized Addresses In Static Mode: A MAC address that you specifically authorize with the mac-address parameter cannot age-out. Instead, it remains in the port’s authorized- devices list until you take one of the following actions: Remove it with a CLI command; Use the CLI to disable port security on the port; Reset the switch to its default configuration; Reboot without first executing write memory.

While in Static mode, if a port adds a MAC address that you have not specifically authorized (see above example), that address remains in the Authorized list until you take one of the following actions: Remove it with a CLI command; Remove the link and reboot the switch after device detection; Disable port security on that port; Reset the switch to its factory-default configuration.

Caution: When you use static with a device limit greater than the number of MAC addresses you specify with mac-address, an unwanted device can become “authorized”. This can occur because the port, in order to fulfill the number of devices allowed by the address-limitparameter, automatically adds devices it detects until the specified limit is reached.

7-12

Page 132
Image 132
SMC Networks SMC6624M manual Port Security Parameters, Ethernet port-list

SMC6624M specifications

SMC Networks SMC6624M is a robust and versatile managed switch designed to meet the needs of enterprises seeking reliable network solutions. This device features 24 Gigabit Ethernet ports that allow for high-speed data transfer, making it ideal for environments that demand high bandwidth. The SMC6624M is particularly suited for small to medium-sized businesses that require a powerful network backbone to support various applications, including voice, video, and data transmission.

One of the standout features of the SMC6624M is its Layer 2 and Layer 3 switching capabilities, enhancing the flexibility and efficiency of network management. The switch supports VLANs (Virtual Local Area Networks), which allow administrators to segment network traffic for improved security and performance. This capability is essential for organizations looking to optimize their network resources and apply policies that enhance security.

The SMC6624M also integrates advanced Quality of Service (QoS) features, enabling the prioritization of network traffic. This is particularly useful for applications such as VoIP and video conferencing, where maintaining low latency and jitter is crucial for ensuring a seamless user experience. Users can define traffic classes and manage bandwidth allocation, which helps in maintaining the quality of critical applications even during peak usage times.

In terms of connectivity and performance, the SMC6624M includes 4 Gigabit SFP ports, allowing for fiber optic connections to extend network reach and provide flexibility in deployment. The ability to take advantage of high-speed fiber connections means businesses can scale their networks as needed without significant infrastructure changes.

Management options for the SMC6624M are comprehensive. It supports SNMP (Simple Network Management Protocol) for monitoring and managing network performance effectively. Additionally, the switch can be configured using a web-based interface, command-line interface (CLI), or through SNMP, providing flexibility to network administrators with different preferences and expertise.

Furthermore, the SMC6624M is built with a fanless design, which ensures quiet operation and is energy efficient. Its compact form factor and sturdy build make it suitable for installation in various environments, including data centers and office settings.

Overall, the SMC Networks SMC6624M stands out for its combination of speed, flexibility, and management features, making it an excellent choice for businesses looking to enhance their network infrastructure. With a focus on reliability and performance, this managed switch promises to deliver the capabilities that today's modern networks demand.