User manual

Publication 1783-UM003D-EN-E - December 2009 39
Chapter 2
the switch learns the first source MAC ID to use the port. Attempts by any
other MAC ID to access the port will be denied.
If the link becomes inactive, the switch will dynamically relearn the MAC ID to
be secured.
The following table shows the Smartport role and the maximum allowable
MAC IDs.
Static Secure MAC Address (MAC ID)
The other method of limiting MAC IDs is to statically configure a single MAC
ID for a port. This address becomes part of the saved configuration of the
switch. This method provides strong security but requires reconfiguration
whenever the device connected to the port is replaced, because the new device
will have a different MAC ID from the old one.
When you use RSLogix 5000 software to configure the switch Add-on Profile
(AOP), you can use the static secure method. This method is not available with
the Device Manager Web interface.
Security Violations
It is a security violation when one of these situations occurs:
The maximum number of secure MAC addresses that have been
configured for a port have been added to the address table, and a station
whose MAC address is not in the address table attempts to access the
interface.
Smartport Role Number of MAC IDs (max)
Automation Device 1
Automation Device With QoS 1
Desktop for Automation 1
Switch for Automation Not restricted
Router Not restricted
I/P phone+Desktop 3
Access Point Not restricted
Port Mirroring Not restricted
None Not restricted