3com S7906E Installationsanweisungen

Seite von 2621
 
1-9 
blockmac: Adds the source MAC addresses of illegal frames to the blocked MAC addresses list 
and discards frames with blocked source MAC addresses. A blocked MAC address is restored to 
normal after being blocked for three minutes, which is fixed and cannot be changed. 
disableport: Disables the port permanently. 
disableport-temporarily: Disables the port for a specified period of time. Use the port-security 
timer disableport command to set the period. 
Follow these steps to configure the intrusion protection feature: 
To do… 
Use the command… 
Remarks 
Enter system view 
system-view 
— 
Enter interface view 
interface interface-type 
interface-number
 
— 
Configure the intrusion 
protection feature 
port-security intrusion-mode 
blockmac | disableport | 
disableport-temporarily } 
Required 
By default, intrusion protection 
is disabled. 
Return to system view 
quit 
— 
Set the silence timeout during 
which a port remains disabled 
port-security timer 
disableport time-value 
Optional 
20 seconds by default 
 
 
On a port operating in either the macAddressElseUserLoginSecure mode or the 
macAddressElseUserLoginSecureExt mode, intrusion protection is triggered only after both MAC 
authentication and 802.1X authentication for the same frame fail.  
 
Configuring Trapping 
The trapping feature enables a device to send trap information in response to four types of events: 
addresslearned: Learning of a new address. 
dot1xlogfailure/dot1xlogon/dot1xlogoff: 802.1x authentication failure/successful 802.1x 
authentication/802.1x user logoff. 
ralmlogfailure/ralmlogoff: MAC authentication failure/MAC authentication user logoff. 
intrusion: Finding of illegal frames. 
Follow these steps to configure port security trapping: 
To do… 
Use the command… 
Remarks 
Enter system view 
system-view 
— 
Enable port security traps 
port-security trap 
addresslearned | 
dot1xlogfailure | dot1xlogoff 
dot1xlogon intrusion 
ralmlogfailure | ralmlogoff 
ralmlogon } 
Required 
By default, no port security trap 
is enabled.