DGS-3630 Series Layer 3 Stackable Managed Switch Web UI Reference Guide 
456 
 
Figure 9-2 Port Security Port Settings Window 
 
The fields that can be configured are described below: 
Parameter  Description 
Unit 
Select the Switch unit that will be used for this configuration here. 
From Port - To Port 
Select the appropriate port range used for the configuration here. 
State 
Select to enable or disable the port security feature on the port(s) specified. 
Maximum 
Enter the maximum number of secure MAC addresses that will be allowed on the 
port(s) specified. This value must be between 0 and 12288. By default, this value 
is 32. 
Violation Action 
Select the violation action that will be taken here. Options to choose from are 
Protect, Restrict, and Shutdown. 
•  Selecting Protect specifies to drop all packets from the insecure hosts at the 
port-security process level, but does not increment the security-violation 
count. 
•  Selecting Restrict specifies to drop all packets from the insecure hosts at the 
port-security process level and increments the security-violation count and 
record the system log. 
•  Selecting Shutdown specifies to shut down the port if there is a security 
violation and record the system log. 
Security Mode 
Select the security mode option here. Options to choose from are Permanent and 
Delete-on-Timeout. 
•  Selecting Permanent specifies that under this mode, all learned MAC 
addresses will not be purged out unless the user manually deletes those 
entries. 
•  Selecting Delete-on-Timeout specifies that under this mode, all learned 
MAC addresses will be purged out when an entry is aged out or when the 
user manually deletes these entries. 
Aging Time 
Enter the aging time value used for auto-learned dynamic secured addresses on 
the specified port here. This value must be between 0 and 1440 minutes. 
Aging Type 
Select the aging type here. Options to choose from are Absolute and Inactivity. 
•  Selecting Absolute specifies that all the secure addresses on this port age 
out exactly after the time specified and is removed from the secure address 
list. This is the default type. 
•  Selecting Inactivity specifies that the secure addresses on this port age out 
only if there is no data traffic from the secure source address for the