DGS-3630 Series Layer 3 Stackable Managed Switch Web UI Reference Guide
456
Figure 9-2 Port Security Port Settings Window
The fields that can be configured are described below:
Parameter Description
Unit
Select the Switch unit that will be used for this configuration here.
From Port - To Port
Select the appropriate port range used for the configuration here.
State
Select to enable or disable the port security feature on the port(s) specified.
Maximum
Enter the maximum number of secure MAC addresses that will be allowed on the
port(s) specified. This value must be between 0 and 12288. By default, this value
is 32.
Violation Action
Select the violation action that will be taken here. Options to choose from are
Protect, Restrict, and Shutdown.
• Selecting Protect specifies to drop all packets from the insecure hosts at the
port-security process level, but does not increment the security-violation
count.
• Selecting Restrict specifies to drop all packets from the insecure hosts at the
port-security process level and increments the security-violation count and
record the system log.
• Selecting Shutdown specifies to shut down the port if there is a security
violation and record the system log.
Security Mode
Select the security mode option here. Options to choose from are Permanent and
Delete-on-Timeout.
• Selecting Permanent specifies that under this mode, all learned MAC
addresses will not be purged out unless the user manually deletes those
entries.
• Selecting Delete-on-Timeout specifies that under this mode, all learned
MAC addresses will be purged out when an entry is aged out or when the
user manually deletes these entries.
Aging Time
Enter the aging time value used for auto-learned dynamic secured addresses on
the specified port here. This value must be between 0 and 1440 minutes.
Aging Type
Select the aging type here. Options to choose from are Absolute and Inactivity.
• Selecting Absolute specifies that all the secure addresses on this port age
out exactly after the time specified and is removed from the secure address
list. This is the default type.
• Selecting Inactivity specifies that the secure addresses on this port age out
only if there is no data traffic from the secure source address for the