Configuring MAC Locking show maclock
24-2 Security Configuration
•FlowSetupThrottling(FST)—preventstheeffectsofDoSattacksbylimitingthenumberof
neworestablishedflowsthatcanbeprogrammedonanyindividualswitchport.Fordetails,
referto“ConfiguringFlowSetupThrottling(FST)”onpage 24‐25.
Configuring MAC Locking
Purpose
Toreview,disable,enableandconfigureMAClocking.ThislocksaMACaddresstooneormore
ports,preventingconnectionofunauthorizeddevicesviatheport(s).WhensourceMAC
addressesarereceivedonspecifiedports,theswitchdiscardsallsubsequentframesnot
containingtheconfiguredsourceaddresses.Theonlyframesforwarded
ona“locked”portare
thosewiththe“locked”MACaddress(es)forthatport.
Commands
show maclock
UsethiscommandtodisplaythestatusofMAClockingononeormoreports.
Syntax
show maclock [port_string]
Note: Matrix DFE-Gold Series modules allow for up to 32 MAC addresses to be locked per port.
For information about... Refer to page...
show maclock 24-2
show maclock stations 24-4
set maclock enable 24-5
set maclock disable 24-5
set maclock 24-6
set maclock firstarrival 24-7
set maclock move 24-7
clear maclock firstarrival 24-8
set maclock static 24-8
clear maclock static 24-9
set maclock trap 24-9
clear maclock 24-10