
108 Chapter 3 Security
212160-A
Table 53 describes the parameters and variables for the mac-security
command.
mac-security mac-address-table address command
The mac-security mac-address-table address command assigns either
a specific port or a security list to the MAC address. This removes any previous
assignment to the specified MAC address and creates an entry in the BaySecure
table of allowed MAC addresses. The syntax for the
mac-security
mac-address-table address
command is:
mac-security mac-address-table address <H.H.H.> {port
<portnum>|security-list <1-32>}
Table 53 mac-security command parameters and values
Parameters and variables Description
disable|enable Disables or enables MAC address-based security.
filtering {enable|disable} Enables or disables destination address (DA) filtering on intrusion
detected.
intrusion-detect
{enable|disable|forever}
Specifies partitioning of a port when an intrusion is detected:
• enable—port is partitioned for a period of time
• disabled—port is not partitioned on detection
• forever—port is partitioned until manually changed
intrusion-timer <1-65535> Specifies, in seconds, length of time a port is partitioned when an
intrusion is detected; enter the number of you want.
learning-ports <portlist> Specifies MAC address learning. Learned addresses are added
to the table of allowed MAC addresses. Enter the ports you want
to learn; it can be a single port, a range of ports, several ranges,
all, or none.
learning {enable|disable} Specifies MAC address learning:
• enable—enables learning by ports
• disable—disables learning by ports
snmp-lock {enable|disable} Enables or disables a lock on SNMP write-access to the
BaySecure MIBs.
snmp-trap {enable|disable} Enables or disables trap generation upon intrusion detection.
Komentarze do niniejszej Instrukcji