Security
56
2.5
Port Security
RM Web
Release
6.0
07/2010
Figure 17: Port Security dialog
Note: The IP port security operates internally on layer 2. The device
internally translates an allowed IP address into an allowed MAC address
when you enter the IP address. An ARP request is used for this.
Prerequisites for the IP-based port security:
– The device with the allowed IP address supports ARP
– The device can be accessed while configuring IP port security
– The MAC address to which the IP address is assigned is unique and
remains unchanged after the IP address is entered.
If you have entered a router interface as the allowed IP address, all the
packets sent from this interface are considered allowed, since they contain
the same MAC source address.
If a connected device sends packets with the allowed IP address but a
different MAC address, it will not be allowed by the Switch. If you exchange
the device with the allowed IP address for a different one with the same IP
address, enter the IP address in the Switch again so that the Switch learns
the new MAC address.