Mac address security guidelines – Allied Telesis AT-S63 User Manual

Page 640

Advertising
background image

Chapter 27: Port Security

640

Section IV: Port Security

Intrusion action defines what a port does when it receives an invalid frame.
For a port operating under either the Secured or Locked security mode,
the intrusion action is always the same. The port discards the frame.

But with the Limited security mode you can specify an intrusion action.
Here are the options:

ˆ

Discard the invalid frame.

ˆ

Discard the invalid frame and send an SNMP trap. (SNMP must be
enabled on the switch for the trap to be sent.)

ˆ

Discard the invalid frame, send an SNMP trap, and disable the port.

MAC Address

Security

Guidelines

Following are several general guidelines to keep in mind when using this
type of port security:

ˆ

The filtering of a packet occurs on the ingress port, not on the egress
port.

ˆ

MAC address security can be set from a local or Telnet management
session, but not from a web browser management session.

ˆ

You cannot use MAC address security and port-based access control
on the same port.

Advertising