ES-2024 Series User’s Guide
149
CHAPTER 19
Port Security
This chapter shows you how to set up port security.
19.1 Port Security Overview
Port security allows only packets with dynamically learned MAC addresses and/or
configured static MAC addresses to pass through a port on the Switch. See
Chapter 10 on page 105 for information on configuring static MAC address
forwarding.
For maximum port security, enable this feature, disable MAC address learning and
configure static MAC address(es) for a port. By default, MAC address learning is
still enabled even though the port security is not activated.
Functionally the Switch allows for three possible outcomes with port security. You
can configure the ports to:
• Forward all packets and learn all MAC addresses.
• Drop all packets from unknown MAC addresses and do not learn MAC addresses.
• Drop all packets from unknown MAC addresses and learn a limited number of
MAC addresses.
Note: The Switch supports five possible configurations for port security. See Section
19.3 on page 151 for supported configurations and an example.