beautypg.com

Brocade FastIron Ethernet Switch Security Configuration Guide User Manual

Page 8

background image

MAC port security configuration..................................................................219

Enabling the MAC port security feature.......................................... 219
Setting the maximum number of secure MAC addresses for an

interface.....................................................................................219

Setting the port security age timer.................................................. 220
Specifying secure MAC addresses................................................. 221
Autosaving secure MAC addresses to the startup configuration.... 221
Specifying the action taken when a security violation occurs......... 222

Clearing port security statistics................................................................... 223

Clearing restricted MAC addresses................................................ 223
Clearing violation statistics..............................................................223

Displaying port security information ........................................................... 224

Displaying port security settings......................................................224
Displaying the secure MAC addresses........................................... 224
Displaying port security statistics.................................................... 225
Displaying restricted MAC addresses on a port..............................226

MAC-based VLANs..............................................................................................................227

Supported MAC-based VLAN features....................................................... 227
MAC-based VLAN overview........................................................................227

Static and dynamic hosts................................................................ 228
MAC-based VLAN feature structure................................................228

Dynamic MAC-based VLAN........................................................................229

Configuration notes and feature limitations for dynamic MAC-

based VLAN.............................................................................. 229

Dynamic MAC-based VLAN CLI commands...................................229
Dynamic MAC-based VLAN configuration example....................... 230

MAC-based VLAN configuration................................................................. 231

Using MAC-based VLANs and 802.1X securityon the same port ..232
Configuring generic and Brocade vendor-specificattributes on

the RADIUS server....................................................................232

Aging for MAC-based VLAN........................................................... 233
Disabling aging for MAC-based VLAN sessions.............................234
Configuring the maximum MAC addresses per port....................... 235
Configuring a MAC-based VLAN for a static host...........................235
Configuring MAC-based VLAN for a dynamic host.........................236
Configuring dynamic MAC-based VLAN.........................................236

Configuring MAC-based VLANs using SNMP............................................ 237
Displaying Information about MAC-based VLANs...................................... 237

Displaying the MAC-VLAN table..................................................... 237
Displaying the MAC-VLAN table for a specific MAC address......... 238
Displaying allowed MAC addresses................................................238
Displaying denied MAC addresses................................................. 239
Displaying detailed MAC-VLAN data.............................................. 240
Displaying MAC-VLAN information for a specific interface............. 241
Displaying MAC addresses in a MAC-based VLAN .......................242
Displaying MAC-based VLAN logging.............................................242

Clearing MAC-VLAN information................................................................ 243
Sample MAC-based VLAN application....................................................... 243

Defining MAC Address Filters.............................................................................................. 247

Supported MAC address filter features.......................................................247
MAC address filters configuration notes and limitations............................. 247
MAC address filters command syntax.........................................................248
Enabling logging of management traffic permitted by MAC address

filters......................................................................................................249

8

FastIron Ethernet Switch Security Configuration Guide

53-1003088-03