EasyManuals Logo

HP ProCurve 2810 Series Access Security Guide

HP ProCurve 2810 Series
326 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #270 background imageLoading...
Page #270 background image
9-26
Configuring and Monitoring Port Security
MAC Lockout
How It Works. Let’s say a customer knows there are unauthorized wireless
clients who should not have access to the network. The network administrator
“locks out” the MAC addresses for the wireless clients by using the MAC
Lockout command (lockout-mac <mac-address>). When the wireless clients
then attempt to use the network, the switch recognizes the intruding MAC
addresses and prevents them from sending or receiving data on that network.
If a particular MAC address can be identified as unwanted on the switch then
that MAC Address can be disallowed on all ports on that switch with a single
command. You don’t have to configure every single port—just perform the
command on the switch and it is effective for all ports.
MAC Lockout overrides MAC Lockdown, port security, and 802.1X authenti-
cation.
You cannot use MAC Lockout to lock:
Broadcast or Multicast Addresses (Switches do not learn these)
Switch Agents (The switch’s own MAC Address)
If someone using a locked out MAC address tries to send data through the
switch a message is generated in the log file:
Lockout logging format:
W 10/30/03 21:35:15 maclock: module A: 0001e6-1f96c0 detected
on port A15
W 10/30/03 21:35:18 maclock: module A: 0001e6-1f96c0 detected
on port A15
W 10/30/03 21:35:18 maclock: module A: Ceasing lock-out logs
for 5m
As with MAC Lockdown a rate limiting algorithm is used on the log file so that
it does not become overclogged with error messages. (Refer to “Limiting the
Frequency of Log Messages” on page 9-20.)
Displaying status. Locked out ports are listed in the output of the show
running-config command in the CLI. The show lockout-mac command also lists
the locked out MAC addresses, as shown below.

Table of Contents

Other manuals for HP ProCurve 2810 Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the HP ProCurve 2810 Series and is the answer not in the manual?

HP ProCurve 2810 Series Specifications

General IconGeneral
Jumbo Frame SupportYes
ModelHP ProCurve 2810 Series
Ports24 or 48 10/100/1000 ports
Uplink Ports4 SFP (mini-GBIC) slots
Forwarding Rate71.4 Mpps
LayerLayer 2
ManagementWeb, SNMP, CLI
MAC Address Table Size16000 entries
Routing ProtocolStatic IP routing
Form FactorRack-mountable
Power Consumption48W (24-port)
Operating Temperature32°F to 0°F (0°C to 0°C)
Operating Humidity15% to 95% non-condensing
Power SupplyInternal power supply

Related product manuals