64 Switch Features
Dot1x Monitor Mode
Monitor mode can be enabled in conjunction with Dot1x authentication to 
allow network access even when the user fails to authenticate. The switch logs 
the results of the authentication process for diagnostic purposes. The main 
purpose of this mode is to help troubleshoot the configuration of a Dot1x 
authentication on the switch without affecting the network access to the 
users of the switch.
For information about enabling the Dot1X Monitor mode, see "Configuring 
Port and System Security" on page 469.
MAC-Based Port Security
The port security feature limits access on a port to users with specific MAC 
addresses. These addresses are manually defined or learned on that port. 
When a frame is seen on a locked port, and the frame source MAC address is 
not tied to that port, the protection mechanism is invoked.
For information about configuring MAC-based port security, see "Configuring 
Port and System Security" on page 469.
Access Control Lists (ACL)
Access Control Lists (ACLs) ensure that only authorized users have access to 
specific resources while blocking off any unwarranted attempts to reach 
network resources. ACLs are used to provide traffic flow control, restrict 
contents of routing updates, decide which types of traffic are forwarded or 
blocked, and above all provide security for the network. The switch supports 
the following ACL types:
•IPv4 ACLs
•IPv6 ACLs
• MAC ACLs
For all ACL types, you can apply the ACL rule when the packet enters or exits 
the physical port, LAG, or VLAN interface.
For information about configuring ACLs, see "Configuring Access Control 
Lists" on page 513.