EasyManuals Logo

Enterasys D2 D2G124-12P User Manual

Enterasys D2 D2G124-12P
496 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #470 background imageLoading...
Page #470 background image
Configuring MAC Locking
15-46 Security Configuration
Configuring MAC Locking
ThisfeaturelocksaMACaddresstooneormoreports,preventingconnectionofunauthorized
devicesthroughtheport(s).WhensourceMACaddressesarereceivedonspecifiedports,the
switchdiscardsallsubsequentframes notcontainingtheconfiguredsourceaddresses.Theonly
framesforwardedona“locked”portarethosewith
the“locked”MACaddress(es)forthatport.
TherearetwomethodsoflockingaMACtoaport:firstarrivalandstatic.Thefirstarrivalmethod
isdefinedtobelockingthefirstnnumberofMACswhicharriveonaportconfiguredwithMAC
lockingenabled.Thevaluenis
configuredwiththesetmaclockfirstarrivalcommand.
ThestaticmethodisdefinedtobestaticallyprovisioningaMACportlockusingthesetmaclock
command.ThemaximumnumberofstaticMACaddressesallowedforMAClockingonaport
canbeconfiguredwiththesetmaclockstaticcommand.
Youcanconfigure
theswitchtoissueaviolationtrapifapacketarriveswithasourceMAC
addressdifferentfromanyofthecurrentlylockedMACaddressesforthatport.
MACsareunlockedasaresultof:
•Alinkdownevent
•WhenMAClock ingisdisabledonaport
•WhenaMACisaged
outoftheforwardingdatabasewhenFirstArrivalagingisenabled
Whenproperlyconfigured,MAClockingisanexcellentsecuritytoolasitpreventsMACspoofing
onconfiguredports.AlsoifaMACweretobesecuredbysomethinglikeDragonDynamic
IntrusionDetection,MAClockingwouldmakeitmoredifficultfor
ahackertosendpacketsinto
thenetworkbecausethehackerwouldhavetochangetheirMACaddressandmovetoanother
port.Inthemeantimethesystemadministratorwouldbereceivingamaclocktrapnotification.
Purpose
Toreview,disable,enable,andconfigureMAClocking.
Commands
authenticated mac
address
If authentication has succeeded, displays the MAC address assigned for egress.
vlan id If authentication has succeeded, displays the assigned VLAN id for ingress.
Table 15-50 show vlanauthorization Output Details (Continued)
Output Field What It Displays...
For information about... Refer to page...
show maclock 15-47
show maclock stations 15-48
set maclock enable 15-49
set maclock disable 15-50
set maclock 15-50
clear maclock 15-51

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Enterasys D2 D2G124-12P and is the answer not in the manual?

Enterasys D2 D2G124-12P Specifications

General IconGeneral
BrandEnterasys
ModelD2 D2G124-12P
CategoryNetwork Router
LanguageEnglish

Related product manuals