set maclock firstarrival
SecureStack C2 Configuration Guide 23-57
Parameters
Defaults
None.
Mode
Switchcommand,read‐write.
Example
ThisexampleshowshowtoresetthenumberofallowablestaticMACsonfe.2.3:
C2(rw)->clear maclock static fe.2.3
set maclock firstarrival
UsethiscommandtorestrictMAClockingonaporttoamaximumnumberofendstation
addressesfirstconnectedtothatport.
Syntax
set maclock firstarrival port-string value
Parameters
Defaults
None.
Mode
Switchcommand,read‐write.
Usage
Themaclockfirstarrivalcountresetswhenthelinkgoesdown.Thisfeatureisbeneficialifyou
haveroamingusers—thefirstarrivalcountwillbereseteverytimeausermovestoanotherport,
butwillstillprotectagainstconnectingmultipledevicesonasingleportandwillprotectagainst
MAC
addressspoofing.
port‐string SpecifiestheportonwhichtoresetnumberofstaticMACaddresses
allowed.Foradetaileddescriptionofpossibleport‐stringvalues,referto
“PortStringSyntaxUsedintheCLI”onpage 7‐2.
port‐string SpecifiestheportonwhichtolimitMAClocking.Foradetailed
descriptionofpossibleport‐stringvalues,referto“PortStringSyntaxUsed
intheCLI”onpage 7‐2.
value SpecifiesthenumberoffirstarrivalendstationMACaddressestobe
allowedconnectionstotheport.Valid
valuesare0to600.
Note: Setting a port’s first arrival limit to 0 does not deny the first MAC address learned on the port
from passing traffic.