Comware Based
1753931 Members
10131 Online
108810 Solutions
New Discussion юеВ

Switch HPE 5130 EI : Port-security

 
SOLVED
Go to solution
Damfive
Occasional Advisor

Switch HPE 5130 EI : Port-security

Hello,

I create this new topic concerning our new switches, as we changed 3 weeks ago.

We configured the port-security on our switches, Our infrastructure works with a Radius Server, with Mac Authentification.

The problem is : The PORTSEC events are not showing in the logs, and I search everywhere a documentation concerning this topic, but nothing helps... All the documentations are related to the Port-security configuration, but not about the event displaying in the logs.

If someone could give me his light, I would be very grateful.

Thanks,

 

Damien

12 REPLIES 12
Ivan_B
HPE Pro

Re: Switch HPE 5130 EI : Port-security

Hello!

Update to the latest version and check the " port-security access-user log enable" command, it seems to be what you are looking for - https://support.hpe.com/hpesc/public/docDisplay?docLocale=en_US&docId=a00017793en_us Also, be sure you do not have "info-center source portsec logfile deny" command enabled.

Hope it helps!

 

I am an HPE employee

Accept or Kudo

Damfive
Occasional Advisor

Re: Switch HPE 5130 EI : Port-security

Hello Ivan, first of all many thanks for your quick answer !

I just type the command and don't see any approvments for the moment, but I will search from my side what I can do and will come back to you !

See you soon !

Damfive
Occasional Advisor

Re: Switch HPE 5130 EI : Port-security

Hey, I read everything about port-security in your documentation (thanks for that), and yes this command seems to be the good one really !

But nothing changed. I tried to add also : info-center source PORTSEC logfile level informational but not joy.

I was pretty sure to have a good configuration in my switch as we used approximativly the same configuration with our old HPE switches.

In some websites, I saw some people just enable the port-security , put it on the interfaces and BIM, they have it appearing...

I would prefer it in my case... haha

So maybe we can check my port-security configuration together, or do you think update the switch in latest version could fix the problem?

PS : Version of the Switch "Version 7.1.0.070, Release 350P02"

Thank you,

 

Damien

 

Ivan_B
HPE Pro

Re: Switch HPE 5130 EI : Port-security

Could you re-check the s/w version? It should have 4 numbers before P02.

 

I am an HPE employee

Accept or Kudo

Damfive
Occasional Advisor

Re: Switch HPE 5130 EI : Port-security

Sorry Ivan I missed one : 3506

Ivan_B
HPE Pro
Solution

Re: Switch HPE 5130 EI : Port-security

I see, so you already have the latest version installed. Basically, in order to achieve what you want - port security events logging, you need 3 commands, each enables logging for the respective module that is dependent from port-security:

port-security access-user log enable
dot1x access-user log enable
mac-authentication access-user log enable

Please, check if you have all three, despite the fact you didn't mention dot1x, but try to set all of them. It should help, unless I am missing something specific for this particular platform.

If that won't help, I think the best way to proceed will be to contact our Support line and log a case for this issue.

 

I am an HPE employee

Accept or Kudo

Damfive
Occasional Advisor

Re: Switch HPE 5130 EI : Port-security

Hello Ivan, I just entered the 3 commands that you send to me, and nothing help...

I already tried to contact the online service, and when I choose my switch model, It tells me that they don't support this model for the moment...

Anyway, thanks for your help Ivan,  if you have anything helping, I will be there ! haha

Damien

Damfive
Occasional Advisor

Re: Switch HPE 5130 EI : Port-security

I tried to open a case : Not in their scope because of Standard Warranty.

But I'm wondering if it's not a bug of the latest version, nobody has the same problem here ?

Damien

Ivan_B
HPE Pro

Re: Switch HPE 5130 EI : Port-security

Hello Damien!

To be honest I am not sure what exactly happened during the case opening, maybe they considered the case as configuration assistance, but in fact it is not, because you have followed configuration and command reference guides, set all the commands as required, but the configuration didn't work as described in the guide. Insist that it is a "break and fix" case and it should be covered by the standard warranty, as product functionality is impacted - advertised features do not work.

Just FYI, you have Lifetime warranty for the switch, as long as you are the original buyer ("as long as owned" clause - "For products purchased after December 1, 2014, the warranty extends only for as long as the original end user owns the product. Includes coverage of any built-in fans and power supplies for the entire warranty period. You may be required to provide proof of purchase or lease as a condition of receiving warranty service.") and it includes Business Hours Technical support - "Warranty phone and electronic case technical support is provided during local HPE business hours for the entire warranty period for the purposes of initiating the RMA process, diagnosing hardware or software defects. HPE will provide next business day email response for the purposes of diagnosing hardware or software defects during standard local business hours for the first 90 days after purchase. See productтАЩs Limited Warranty Statement for additional coverage details. Extended coverage services are available." More details here - https://support.hpe.com/hpesc/public/docDisplay?docId=c04499781

If our Support Agent won't agree, write down his name and escalate the issue to his manager. Maybe they have other reasons to refuse, I do not know, but on your place I'd definitely try to push the case and get at least a meaningful explanation.

Unfortunately, I do not deal with opening cases and can't help you directly

 

I am an HPE employee

Accept or Kudo