
Selecting the Security Violation Mode Configuring Learned Port Security
page 4-10 OmniSwitch 6800/6850/9000 Network Configuration Guide June 2006
Selecting the Security Violation Mode
By default, the security violation mode for an LPS port is set to restrict. In this mode, when an unautho-
rized MAC address is received on an LPS port, the packet containing the address is blocked. However, all
other packets that contain an authorized source MAC address are allowed to forward on the port.
Note that unauthorized source MAC addresses are not learned in the LPS table but are still recorded in the
source learning MAC address table with a filtered operational status. This allows the user to view MAC
addresses that were attempting unauthorized access to the LPS port.
The other violation mode option is shutdown. In this mode, the LPS port is disabled when an unautho-
rized MAC address is received; all traffic is prevented from forwarding on the port. After a shutdown
occurs, a manual reset is required to return the port back to normal operation.
To configure the security violation mode for an LPS port, enter port-security followed by the port’s
slot/port designation, then violation followed by restrict or shutdown. For example, the following
command selects the shutdown mode for port 1 on slot 4:
-> port-security 4/1 violation shutdown
To configure the security violation mode for multiple LPS ports, specify a range of ports or multiple slots.
For example:
-> port-security 4/1-10 violation shutdown
-> port-security 1/10-15 2/1-10 violation restrict
Displaying Learned Port Security Information
To display LPS port and table information, use the show commands listed below:
For more information about the resulting display from these commands, see the OmniSwitch CLI Refer-
ence Guide. An example of the output for the show port-security and show port-security shutdown
commands is also given in “Sample Learned Port Security Configuration” on page 4-3.
show port-security Displays Learned Port Security configuration values as well as
MAC addresses learned on the port.
show port-security shutdown Displays the current time limit value set for source learning on all
LPS enabled ports.
Kommentare zu diesen Handbüchern