ProCurve Series 2300 and 2500 Switches Release Notes

229
Enhancements in Release F.02.02
Port Security: Changes to Retaining Learned Static Addresses Across a Reboot
After you configure the authorized MAC addresses you want on a port, execute the write
memory command to make these addresses permanent in the switch’s configuration. (See
the "Assigned/Authorized Address" bullet under "Retention of Static Addresses" in the next
subsection.)
Retention of Static Addresses
Beginning with release F.02.02, port security operation has changed to the operation described below.
These changes affect information provided in Table 7-1, "Port Security Parameters" on pages 7-14 and
7-15 in the Management and Configuration Guide (p/n 5969-2354) provided for the Series 2500
switches.
Learned Addresses: In the following two cases, a port in Static learn mode retains a learned
MAC address even if you subsequently reboot the switch or disable port security for that port:
The port learns a MAC address after you configure the port for Static learn mode in both
the startup-config file and the running-config files (by executing the
write memory
command).
The port learns a MAC address after you configure the port for Static learn mode in only
the running-config file and, after the address is learned, you execute
write memory to
configure the startup-config file to match the running-config file.
To remove an address learned using either of the preceding methods, do one of the following:
Delete the address by using the
no port-security <port-number> mac-address <mac-addr>
command.
Download a previously saved configuration file that does not include the unwanted MAC
address assignment.
Reset the switch to its factory-default configuration.
Assigned/Authorized Address: If you manually assign a MAC address (using the port-
security <port-number> address-list <mac-addr>
command) and then you execute a write memory
command, the assigned MAC address remains in memory until you do one of the following:
Delete it by using the
no port-security <port-number> mac-address <mac-addr> command.
Download a previously saved configuration file that does not include the unwanted MAC
address assignment.
Reset the switch to its factory-default configuration.
Disabling port security on a port does not remove an assigned MAC address from the port security
configuration for that port.