EasyManua.ls Logo

Enterasys D-Series

Enterasys D-Series
540 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
Configuring MAC Locking
Enterasys D-Series CLI Reference 17-51
Configuring MAC Locking
ThisfeaturelocksaMACaddresstooneormoreports,preventingconnectionofunauthorized
devicesthroughtheport(s).WhensourceMACaddressesarereceivedonspecifiedports,the
switchdiscardsallsubsequentframes notcontainingtheconfiguredsourceaddresses.Theonly
framesforwardedona“locked”portarethosewith
the“locked”MACaddress(es)forthatport.
TherearetwomethodsoflockingaMACtoaport:firstarrivalandstatic.Thefirstarrivalmethod
isdefinedtobelockingthefirstnnumberofMACswhicharriveonaportconfiguredwithMAC
lockingenabled.Thevaluenis
configuredwiththesetmaclockfirstarrivalcommand.
ThestaticmethodisdefinedtobestaticallyprovisioningaMACportlockusingthesetmaclock
command.ThemaximumnumberofstaticMACaddressesallowedforMAClockingonaport
canbeconfiguredwiththesetmaclockstaticcommand.
Youcanconfigure
theswitchtoissueaviolationtrapifapacketarriveswithasourceMAC
addressdifferentfromanyofthecurrentlylockedMACaddressesforthatport.
MACsareunlockedasaresultof:
•Alinkdownevent
•WhenMAClock ing isdisabledonaport
•WhenaMACisaged
outoftheforwardingdatabasewhenFirstArrivalagingisenabled
Whenproperlyconfigured,MAClockingisanexcellentsecuritytoolasitpreventsMACspoofing
onconfiguredports.AlsoifaMACweretobesecuredbysomethinglikeDragonDynamic
IntrusionDetection,MAClockingwouldmakeitmoredifficultfor
ahackertosendpacketsinto
thenetworkbecausethehackerwouldhavetochangetheirMACaddressandmovetoanother
port.Inthemeantimethesystemadministratorwouldbereceivingamaclocktrapnotification.
Purpose
Toreview,disable,enable,andconfigureMAClocking.
Commands
For information about... Refer to page...
show maclock 17-52
show maclock stations 17-53
set maclock enable 17-54
set maclock disable 17-55
set maclock 17-55
clear maclock 17-56
set maclock static 17-57
clear maclock static 17-57
set maclock firstarrival 17-58
clear maclock firstarrival 17-59
set maclock agefirstarrival 17-59
clear maclock agefirstarrival 17-60

Table of Contents

Related product manuals