<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: automating mac lockout in Switches, Hubs, and Modems</title>
    <link>https://community.hpe.com/t5/switches-hubs-and-modems/automating-mac-lockout/m-p/4529698#M20433</link>
    <description>thanks for the discussion.  Looks like I will need to continue with manual lockout until I get IDM up and running.  I was hoping there would be an easy way to restrict port access to a known mac addresses when the device became active on the network. Port security would have been my first choice but there doesn't appear to be a way to automatically clear the flag and return the port for use when the original device was plugged back in.</description>
    <pubDate>Wed, 11 Nov 2009 20:38:27 GMT</pubDate>
    <dc:creator>Dave Henley</dc:creator>
    <dc:date>2009-11-11T20:38:27Z</dc:date>
    <item>
      <title>automating mac lockout</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/automating-mac-lockout/m-p/4529690#M20425</link>
      <description>Is it possible to create a policy in PCM+ 3.0 that will automatically Lockout a known mac address on a group of 5400 switches when connected then automatically UnLock the port after a given time period?  &lt;BR /&gt;</description>
      <pubDate>Sat, 07 Nov 2009 17:52:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/automating-mac-lockout/m-p/4529690#M20425</guid>
      <dc:creator>Dave Henley</dc:creator>
      <dc:date>2009-11-07T17:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: automating mac lockout</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/automating-mac-lockout/m-p/4529691#M20426</link>
      <description>This should be possible, but i'm not 100% sure if this roll-back function is part of network Immunity Manager 2.0 or already available in PCM+ 3.0. Check if you can create the Mac lock-out action in the policy manager.&lt;BR /&gt;&lt;BR /&gt;You can test by downloading the 60 day trial from the procurve website.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 09 Nov 2009 08:30:09 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/automating-mac-lockout/m-p/4529691#M20426</guid>
      <dc:creator>Sietze Reitsma</dc:creator>
      <dc:date>2009-11-09T08:30:09Z</dc:date>
    </item>
    <item>
      <title>Re: automating mac lockout</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/automating-mac-lockout/m-p/4529692#M20427</link>
      <description>I already have PCM+ 3.0 and the mac lockout option is available for use in the Policy Manager.  &lt;BR /&gt;&lt;BR /&gt;I have looked at the events entry but do not see anything that records the mac address of a device connecting to a switch.  Is there a log file that shows more detailed information?&lt;BR /&gt;</description>
      <pubDate>Mon, 09 Nov 2009 14:27:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/automating-mac-lockout/m-p/4529692#M20427</guid>
      <dc:creator>Dave Henley</dc:creator>
      <dc:date>2009-11-09T14:27:43Z</dc:date>
    </item>
    <item>
      <title>Re: automating mac lockout</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/automating-mac-lockout/m-p/4529693#M20428</link>
      <description>only way i can see at the moment is to trigger a mac lockout by a trap. If the event contains the mac address then you can create a policy which captures this mac address for the mac lock-out action. In that case you can create a time based roll-back in the policy, for example one hour.&lt;BR /&gt;&lt;BR /&gt;So in the case of NIM 2.0, you have several triggers like NBAD (Network Behavior Anomaly Detection), external IPS/IDS, or other applications which can be used to perform actions like Mac-lockout, rate limiting or configuring vlans.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 10 Nov 2009 00:49:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/automating-mac-lockout/m-p/4529693#M20428</guid>
      <dc:creator>Sietze Reitsma</dc:creator>
      <dc:date>2009-11-10T00:49:02Z</dc:date>
    </item>
    <item>
      <title>Re: automating mac lockout</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/automating-mac-lockout/m-p/4529694#M20429</link>
      <description>The problem appears to center around getting a mac address to be registered in an event when a device becomes active on a switch.  What type of activity would cause an event and record a mac address?</description>
      <pubDate>Tue, 10 Nov 2009 04:26:48 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/automating-mac-lockout/m-p/4529694#M20429</guid>
      <dc:creator>Dave Henley</dc:creator>
      <dc:date>2009-11-10T04:26:48Z</dc:date>
    </item>
    <item>
      <title>Re: automating mac lockout</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/automating-mac-lockout/m-p/4529695#M20430</link>
      <description>Traps from the switch like portsecurity, dhcp snooping, arp spoofing and NIM events. &lt;BR /&gt;&lt;BR /&gt;Reading: &lt;A href="http://h40060.www4.hp.com/procurve/uk/en/pdfs/application-notes/AN-S16_ProCurve-NIM-policy-mgmt-final-093008.pdf" target="_blank"&gt;http://h40060.www4.hp.com/procurve/uk/en/pdfs/application-notes/AN-S16_ProCurve-NIM-policy-mgmt-final-093008.pdf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.procurve.com/NR/rdonlyres/4C3E6B65-86EA-4436-AEED-ADCF4AA75EBB/0/NetworkImmunityManagerEventInterpretationTechBrief_Dec_07_WW_Eng_A4.pdf?jumpid=reg_R1002_USEN" target="_blank"&gt;http://www.procurve.com/NR/rdonlyres/4C3E6B65-86EA-4436-AEED-ADCF4AA75EBB/0/NetworkImmunityManagerEventInterpretationTechBrief_Dec_07_WW_Eng_A4.pdf?jumpid=reg_R1002_USEN&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;If you clarify what your goal is, then we can search for a solution.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 11 Nov 2009 00:28:16 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/automating-mac-lockout/m-p/4529695#M20430</guid>
      <dc:creator>Sietze Reitsma</dc:creator>
      <dc:date>2009-11-11T00:28:16Z</dc:date>
    </item>
    <item>
      <title>Re: automating mac lockout</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/automating-mac-lockout/m-p/4529696#M20431</link>
      <description>thanks for keeping up with this.  The goal is to lockout a device with a known mac address when that device is plugged into the network and then unlockout after a specified time period.  &lt;BR /&gt;&lt;BR /&gt;or, be able to automatically enable a port in a specified time period after the number of devices that can attach to a port has been exceeded.&lt;BR /&gt;&lt;BR /&gt;Similar to specifying the number of devices that can attach to a switch port before an action is taken.  Problem with this approach is I have to manually remove the flag and enable the port.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 11 Nov 2009 14:28:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/automating-mac-lockout/m-p/4529696#M20431</guid>
      <dc:creator>Dave Henley</dc:creator>
      <dc:date>2009-11-11T14:28:30Z</dc:date>
    </item>
    <item>
      <title>Re: automating mac lockout</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/automating-mac-lockout/m-p/4529697#M20432</link>
      <description>&amp;gt;thanks for keeping up with this. The goal is to lockout a device with a known mac address when that device is plugged into the network and then unlockout after a specified time period. &lt;BR /&gt;&lt;BR /&gt;answ: at the moment a little complicated to create, but it should be possible in the future with a new enhanced scripting engine in PCM3. For now you can manual enable and disable mac lockout. &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;or, be able to automatically enable a port in a specified time period after the number of devices that can attach to a port has been exceeded. &lt;BR /&gt;&lt;BR /&gt;answ: maybe port security can help with a continous learnmode of a number of max clients&lt;BR /&gt;switch (config)# port-security 1 address-limit 8 learnmode limited continuous&lt;BR /&gt;&lt;BR /&gt;The 9th client will be disabled. &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Similar to specifying the number of devices that can attach to a switch port before an action is taken. Problem with this approach is I have to manually remove the flag and enable the port. &lt;BR /&gt;&lt;BR /&gt;answ: see response to your 2nd question&lt;BR /&gt;&lt;BR /&gt;Maybe another idea is to use mac authentication. In this case only registered mac adresses are allowed and unwanted mac adresses can be moved to a policy with less bandwith and/or restricted resource availability. Like internet only. unknown adresses are handled in a separate part of the network or not granted for access.&lt;BR /&gt;&lt;BR /&gt;Sietze&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 11 Nov 2009 20:05:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/automating-mac-lockout/m-p/4529697#M20432</guid>
      <dc:creator>Sietze Reitsma</dc:creator>
      <dc:date>2009-11-11T20:05:13Z</dc:date>
    </item>
    <item>
      <title>Re: automating mac lockout</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/automating-mac-lockout/m-p/4529698#M20433</link>
      <description>thanks for the discussion.  Looks like I will need to continue with manual lockout until I get IDM up and running.  I was hoping there would be an easy way to restrict port access to a known mac addresses when the device became active on the network. Port security would have been my first choice but there doesn't appear to be a way to automatically clear the flag and return the port for use when the original device was plugged back in.</description>
      <pubDate>Wed, 11 Nov 2009 20:38:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/automating-mac-lockout/m-p/4529698#M20433</guid>
      <dc:creator>Dave Henley</dc:creator>
      <dc:date>2009-11-11T20:38:27Z</dc:date>
    </item>
  </channel>
</rss>

