Command Mode

Interface Configuration (Ethernet)

Command Usage

If you enable port security, the switch stops dynamically learning new addresses on the specified port. Only incoming traffic with source addresses already stored in the dynamic or static address table are accepted.

To use port security, first allow the switch to dynamically learn the <source MAC address, VLAN> pair for frames received on a port for an initial training period, and then enable port security to stop address learning. Be sure you enable the learning function long enough to ensure that all valid VLAN members have been registered on the selected port.

To add new VLAN members at a later time, you can manually add secure addresses with the mac-address-table static command, or turn off port security to reenable the learning function long enough for new VLAN members to be registered. Learning may then be disabled again, if desired, for security.

A secure port has the following restrictions:

Cannot use port monitoring.

Cannot be a multi-VLAN port.

Cannot be connected to a network interconnection device.

Cannot be a trunk port.

Example

The following example enables port security of port SNP5:

Console(config)#interface ethernet SNP5

Console(config-if)#port security

Related Commands

mac-address-table static (4-99)

show mac-address-table(4-100)

4-104Sun Fire B1600 Blade System Chassis Switch Administration Guide • June 2003

Page 302
Image 302
Sunfire B1600 manual Following example enables port security of port SNP5