C
LIENT

S

ECURITY

7-2

This switch provides client security using the following options:
Private VLANs – Provide port-based security and isolation between
ports within the assigned VLAN. (See “Configuring Private VLANs” on
page 13-18.)
802.1X – Use IEEE 802.1X port authentication to control access to
specific ports. (See “Configuring 802.1X Port Authentication” on
page 6-19.)
Port Security – Configure secure addresses for individual ports.
IP Source Guard – Filters IP traffic on unsecure ports for which the
source address cannot be identified via static source bindings nor DHCP
snooping.
DHCP Snooping – Filters untrusted DHCP messages on unsecure ports
by building and maintaining a DHCP snooping binding table.
Packet Filtering – Filters packets with specified IP/MAC addresses,
NetBIOS packets, and DHCP requests or replies.
Note: The priority of execution for the filtering commands is Port
Security, Packet Filtering, IP Source Guard, and then DHCP
Snooping.
Configuring Port Security
Port security is a feature that allows you to configure a switch port with
one or more device MAC addresses that are authorized to access the
network through that port.
When port security is enabled on a port, the switch stops learning new
MAC addresses on the specified port when it has reached a configured
maximum number. Only incoming traffic with source addresses already
stored in the dynamic or static address table will be accepted as authorized
to access the network through that port. If a device with an unauthorized
MAC address attempts to use the switch port, the intrusion will be
detected and the switch can automatically take action by disabling the port
and sending a trap message.