EasyManua.ls Logo

Enterasys D2 D2G124-12P

Enterasys D2 D2G124-12P
496 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
Configuring MAC Locking
15-46 Security Configuration
Configuring MAC Locking
ThisfeaturelocksaMACaddresstooneormoreports,preventingconnectionofunauthorized
devicesthroughtheport(s).WhensourceMACaddressesarereceivedonspecifiedports,the
switchdiscardsallsubsequentframes notcontainingtheconfiguredsourceaddresses.Theonly
framesforwardedona“locked”portarethosewith
the“locked”MACaddress(es)forthatport.
TherearetwomethodsoflockingaMACtoaport:firstarrivalandstatic.Thefirstarrivalmethod
isdefinedtobelockingthefirstnnumberofMACswhicharriveonaportconfiguredwithMAC
lockingenabled.Thevaluenis
configuredwiththesetmaclockfirstarrivalcommand.
ThestaticmethodisdefinedtobestaticallyprovisioningaMACportlockusingthesetmaclock
command.ThemaximumnumberofstaticMACaddressesallowedforMAClockingonaport
canbeconfiguredwiththesetmaclockstaticcommand.
Youcanconfigure
theswitchtoissueaviolationtrapifapacketarriveswithasourceMAC
addressdifferentfromanyofthecurrentlylockedMACaddressesforthatport.
MACsareunlockedasaresultof:
•Alinkdownevent
•WhenMAClock ingisdisabledonaport
•WhenaMACisaged
outoftheforwardingdatabasewhenFirstArrivalagingisenabled
Whenproperlyconfigured,MAClockingisanexcellentsecuritytoolasitpreventsMACspoofing
onconfiguredports.AlsoifaMACweretobesecuredbysomethinglikeDragonDynamic
IntrusionDetection,MAClockingwouldmakeitmoredifficultfor
ahackertosendpacketsinto
thenetworkbecausethehackerwouldhavetochangetheirMACaddressandmovetoanother
port.Inthemeantimethesystemadministratorwouldbereceivingamaclocktrapnotification.
Purpose
Toreview,disable,enable,andconfigureMAClocking.
Commands
authenticated mac
address
If authentication has succeeded, displays the MAC address assigned for egress.
vlan id If authentication has succeeded, displays the assigned VLAN id for ingress.
Table 15-50 show vlanauthorization Output Details (Continued)
Output Field What It Displays...
For information about... Refer to page...
show maclock 15-47
show maclock stations 15-48
set maclock enable 15-49
set maclock disable 15-50
set maclock 15-50
clear maclock 15-51

Table of Contents

Related product manuals