Security

last person joined: yesterday 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).

Port-Security configuration

This thread has been viewed 7 times
  • 1.  Port-Security configuration

    Posted Aug 31, 2019 03:01 AM

    Hello,

     

    I am setting up port security. 

     

    I want to be able to learn the MAC as devices are connected up to a predefined limit. If they change after being learned or something something is added I want the port to disable and get an SNMP notification.

     

    I know I cannot configure it on trunks because of the disable action. I believe I can configure it on ports that have things like hubs and mini switches, but I would need to use an alarm action, not the disable.

     

    Would I need to do something along the lines of this to have port security learn the MAC first like this:

     

    port-security (Interface) learn-mode limited-continuous address-limit 2 action send-disable

     

    After it has learned the MAC, how can I change it to static, but to keep the MAC it has learned? Or am I going to have to do the command with limited-continuous then take the MACs it learns and manually enter static and the mac-address (MAC)?