Specifications

Configuring MAC Locking
21-46 Security Configuration
Configuring MAC Locking
Purpose
Toreview,disable,enable,andconfigureMAClocking.ThisfeaturelocksaMACaddresstoone
ormoreports,preventingconnectionofunauthorizeddevicesthroughtheport(s).Whensource
MACaddressesarereceivedonspecifiedports,theswitchdiscardsallsubseq uent framesnot
containingtheconfiguredsourceaddresses.Theonlyframes
forwardedona“locked”portare
thosewiththe“locked”MACaddress(es)forthatport.
Whenproperlyconfigured,MAClockingisanexcellentsecuritytoolasitpreventsMACspoofing
onconfiguredports.AlsoifaMACweretobesecuredbysomethinglikeDragonDynamic
IntrusionDetection,MAClockingwould
makeitmoredifficultforahackertosendpacketsinto
thenetworkbecausethehackerwouldhavetochangetheirMACaddressandmovetoanother
port.Inthemeantimethesystemadministratorwouldbe receivingamaclocktrapnotification.
Commands
ThecommandsneededtoconfigureMAClockingarelistedbelow:
For information about... Refer to page...
show maclock 21-47
show maclock stations 21-48
set maclock enable 21-49
set maclock disable 21-50
set maclock 21-50
clear maclock 21-51
set maclock static 21-52
clear maclock static 21-52
set maclock firstarrival 21-53
clear maclock firstarrival 21-54
set maclock move 21-54
set maclock trap 21-55