H3c-technologies H3C WX6000 Series Access Controllers Manual de usuario Pagina 140

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 678
  • Tabla de contenidos
  • SOLUCIÓN DE PROBLEMAS
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 139
19-1
19 Port Security Configuration
When configuring port security, go to these sections for information you are interested in:
z Introduction to Port Security
z Port Security Configuration Task List
z Displaying and Maintaining Port Security
z Port Security Configuration Examples
z Troubleshooting Port Security
The term switch in this document refers to a switch in a generic sense or an access controller
configured with the switching function unless otherwise specified.
Introduction to Port Security
Port Security Overview
Port security is a MAC address-based security mechanism for network access controlling. It is an
extension to the existing 802.1x authentication and MAC authentication. It controls the access of
unauthorized devices to the network by checking the source MAC address of an inbound frame and the
access to unauthorized devices by checking the destination MAC address of an outbound frame.
With port security, you can define various port security modes to make a device learn only legal source
MAC addresses, so that you can implement different network security management as needed. When a
port security-enabled device detects an illegal frame, it triggers the corresponding port security feature
and takes a pre-defined action automatically. This reduces your maintenance workload and greatly
enhances system security.
The following types of frames are classified as illegal:
z Received frames with unknown source MAC addresses when MAC address learning is disabled.
z Received frames with unknown source MAC addresses when the number of MAC addresses
learned by the port has already reached the upper limit.
z Frames from unauthenticated users.
Port Security Features
NTK
The need to know (NTK) feature checks the destination MAC addresses in outbound frames and allows
frames to be sent to only devices passing authentication, thus preventing illegal devices from
intercepting network traffic.
Vista de pagina 139
1 2 ... 135 136 137 138 139 140 141 142 143 144 145 ... 677 678

Comentarios a estos manuales

Sin comentarios