177
The requirements above must be all met. Otherwise, an error message appears when you set a security
mode on the port. On the other hand, after setting a port security mode on a port, you cannot change
any of the configurations above.
• Before you configure the port to operate in autoLearn mode, set the maximum number of secure
MAC addresses allowed on a port.
NOTE:
• With port security disabled, you can configure a port security mode, but your configuration does not
take effect.
• You cannot change the port security mode of a port with users online.
Configuration procedure
Follow these steps to enable any other port security mode:
To do… Use the command… Remarks
Enter system view system-view —
Set an OUI value for user
authentication
port-security oui oui-value index
index-value
Optional
Not configured by default.
The command is required for the
userlogin-withoui mode.
Enter Layer 2 Ethernet
interface view
interface interface-type
interface-number
—
Set the port security mode
port-security port-mode { autolearn |
mac-authentication |
mac-else-userlogin-secure |
mac-else-userlogin-secure-ext | secure
| userlogin | userlogin-secure |
userlogin-secure-ext |
userlogin-secure-or-mac |
userlogin-secure-or-mac-ext |
userlogin-withoui }
Required
By default, a port operates in
noRestrictions mode.
NOTE:
• When a port operates in autoLearn mode, the maximum number of secure MAC addresses cannot be
changed.
• An OUI, as defined by the Institute of Electrical and Electronics En
ineers (IEEE), is the first 24 bits of the
MAC address, which uniquely identifies a device vendor.
• You can configure multiple OUI values. However, a port in userLoginWithOUI mode allows only one
802.1X user and one user whose MAC address contains a specified OUI to pass authentication at the
same time.
• After enabling port security, you can change the port security mode of a port only when the port is
operating in noRestrictions mode, the default mode. To change the port security mode for a port in an
other mode, use the undo port-security port-mode command to restore the default port security mode
first.