<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Accept traffic via a specific mac address in Security e-Series</title>
    <link>https://community.hpe.com/t5/security-e-series/accept-traffic-via-a-specific-mac-address/m-p/6858664#M364</link>
    <description>&lt;P&gt;Can you use Port-Security set it to static then enter the mac address of the switch at the other end of the uplink?&lt;/P&gt;&lt;P&gt;HP literature tells you you can switch off auto-MDIX to protect yourself from this situation - but I don't rate this is a valid approach because it doesn't take a genius to get hold of a cross-over cable to defeat it.&lt;/P&gt;&lt;P&gt;If you have dot1x implemented, I don't see what the problem is? Doesn't that do all the filtering you need?&lt;/P&gt;&lt;P&gt;Could you use track port on Switch1 to monitor a port on Switch2, and if it goes down, disable the uplink port and send an alert so you know what's going on?&lt;/P&gt;&lt;P&gt;Also, your network monitoring should detect if an Access switch goes down anyway, which could make you suspicious.&lt;/P&gt;</description>
    <pubDate>Thu, 12 May 2016 02:02:30 GMT</pubDate>
    <dc:creator>Vince-Whirlwind</dc:creator>
    <dc:date>2016-05-12T02:02:30Z</dc:date>
    <item>
      <title>Accept traffic via a specific mac address</title>
      <link>https://community.hpe.com/t5/security-e-series/accept-traffic-via-a-specific-mac-address/m-p/6856517#M362</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;Just wondering if anyone has come accross this scenario in the past?&lt;/P&gt;&lt;P&gt;We have two switches, switch 1 and switch 2. We would like to allow traffic from all clients connected to switch 2 into switch 1 but&amp;nbsp;only if that traffic has come via switch 2 (i.e. no one has pulled the uplink out of switch 2 and has tried to connect something else to it in which case the traffic should be disguarded).&lt;/P&gt;&lt;P&gt;A couple of further complications, we use 802.1X authenication and we need to be able to apply this form of lockdown to two of the ports on switch 1.&lt;/P&gt;&lt;P&gt;The switch I'm trying to get this working on is a 2620 (J9625A)&lt;/P&gt;&lt;P&gt;Any suggestions?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;NS&lt;/P&gt;</description>
      <pubDate>Wed, 04 May 2016 13:51:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/security-e-series/accept-traffic-via-a-specific-mac-address/m-p/6856517#M362</guid>
      <dc:creator>NetworkSeb</dc:creator>
      <dc:date>2016-05-04T13:51:06Z</dc:date>
    </item>
    <item>
      <title>Re: Accept traffic via a specific mac address</title>
      <link>https://community.hpe.com/t5/security-e-series/accept-traffic-via-a-specific-mac-address/m-p/6858664#M364</link>
      <description>&lt;P&gt;Can you use Port-Security set it to static then enter the mac address of the switch at the other end of the uplink?&lt;/P&gt;&lt;P&gt;HP literature tells you you can switch off auto-MDIX to protect yourself from this situation - but I don't rate this is a valid approach because it doesn't take a genius to get hold of a cross-over cable to defeat it.&lt;/P&gt;&lt;P&gt;If you have dot1x implemented, I don't see what the problem is? Doesn't that do all the filtering you need?&lt;/P&gt;&lt;P&gt;Could you use track port on Switch1 to monitor a port on Switch2, and if it goes down, disable the uplink port and send an alert so you know what's going on?&lt;/P&gt;&lt;P&gt;Also, your network monitoring should detect if an Access switch goes down anyway, which could make you suspicious.&lt;/P&gt;</description>
      <pubDate>Thu, 12 May 2016 02:02:30 GMT</pubDate>
      <guid>https://community.hpe.com/t5/security-e-series/accept-traffic-via-a-specific-mac-address/m-p/6858664#M364</guid>
      <dc:creator>Vince-Whirlwind</dc:creator>
      <dc:date>2016-05-12T02:02:30Z</dc:date>
    </item>
  </channel>
</rss>

