R211x-HP Flexfabric 11900 Security Command Reference

Table Of Contents
120
Intrusion protection mode: NoAction
Max number of secure MAC addresses: Not configured
Current number of secure MAC addresses: 0
Authorization is permitted
Table 12 Command output
Field Descri
p
tion
AutoLearn aging time Sticky MAC address aging timer, in minutes.
Disableport Timeout Silence period (in seconds) of the port that receives illegal packets.
MAC-move
Status of MAC move:
If the function is enabled, this field displays MAC-move is
permitted.
If the function is disabled, this field displays MAC-move is denied.
OUI value List of OUI values allowed for authentication.
Port mode
Port security mode:
noRestrictions.
autoLearn.
macAddressWithRadius.
macAddressElseUserLoginSecure.
macAddressElseUserLoginSecureExt.
secure.
userLogin.
userLoginSecure.
userLoginSecureExt.
macAddressOrUserLoginSecure.
macAddressOrUserLoginSecureExt.
userLoginWithOUI.
NeedToKnow mode
Need to know (NTK) mode:
NeedToKnowOnly—Allows only unicast packets with
authenticated destination MAC addresses.
NeedToKnowWithBroadcast—Allows only unicast packets and
broadcasts with authenticated destination MAC addresses.
NeedToKnowWithMulticast—Allows unicast packets, multicasts,
and broadcasts with authenticated destination MAC addresses.
Disabled—NTK is disabled.
Intrusion protection mode
Intrusion protection action:
BlockMacAddress—Adds the source MAC address of the illegal
packet to the blocked MAC address list.
DisablePort—Shuts down the port that receives illegal packets
permanently.
DisablePortTemporarilyShuts down the port that receives illegal
packets for some time.
NoAction—Performs no intrusion protection.
Max number of secure MAC addresses
Maximum number of secure MAC addresses (or online users) that
port security allows on the port.