Version 6 SuperStack 3 Switch 4400 Management Interface Reference Guide

Table Of Contents
Web Management Interface - Security Network Access Port Security
http://support.3com.com/infodeli/tools/switches/4400/DHA1720-3AAA08/htmweb/accessportsecurity.htm[11/15/2010 3:44:32 PM]
any restrictions.
Learning Off
This allows the secure addresses to be manually configured against the port. The
secure addresses can also be manually pre-configured into the 'No Security' mode
before entering a different mode of operation.
When a port which has been configured to operate in the 'Automatic Learning'
mode and it learns the configured number of addresses then the port security mode
automatically switches to the 'Learning off' mode.
Continuous Learning
MAC addresses are learned continuously by the port until the number of authorised
addresses specified is reached. When this number is exceeded the first address that
was learned by the port is deleted, allowing a new address to be learned.
Automatic Learning
MAC addresses are learned continuously by the port until the number of authorised
addresses specified is reached. When this number is exceeded the port automatically
stops learning addresses and Disconnect Unauthorized Device (DUD) is enabled on
the port.
When a port which has been configured to operate in the 'Automatic Learning'
mode and it learns the configured number of addresses then the port security mode
automatically switches to the 'Learning off' mode.
Network Login
When the user has been successfully authorized, all network traffic is forwarded
through the port without any restrictions.
Network Login (secure)
When the user has been successfully authorized, only network traffic that is received
from the authorized client device is forwarded through the port. The source MAC
address in received packets is used to determine this; all traffic from other network
devices is filtered. Disconnect Unauthorized Device (DUD) is enabled on the port.
Network Login with NBX
This mode allows an NBX phone and a client device to be used on the same Switch
port. The client device is connected to the user port on the NBX phone, which in
turn is connected to the Switch port. Traffic on the NBX phone is automatically
forwarded. Traffic on the client device is forwarded when the user has been
successfully authorized. Disconnect Unauthorized Device (DUD) is enabled on the
port.
Rada (Basic Radius Authenticated Device Access)
Basic Radius Authenticated Device Access (RADA) provides a means of disabling
access, or changing the port QoS forwarding profile and where necessary the VLAN
assignment based purely on central authentication of an end station's MAC address.
In practice this can be used to provide basic RADIUS-based security for hosts which
do not have 802.1X clients installed. Another application would be to isolate
individual PCs that have been identified to contain viruses. This mode should not be
considered a totally secure mode, as it may be bypassed by MAC-address spoofing.
Rada Else Network Login (Secure Network Login with RADA Override)
This mode provides the secure login capability of 802.1X, and also offers an
override capability based on MAC address. This mode is intended for use where
802.1X Network Login is the normal access mechanism, but a means of isolating
hosts is still required for example client virus isolation.
This mode is intended to compliment 802.1X network login, and can be used to
authorise host access to any network resource. It can only be considered secure if