- Community Home
- >
- Networking
- >
- Legacy
- >
- Switches, Hubs, Modems
- >
- Block MAC certain Addresses
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-22-2006 02:31 AM
тАО05-22-2006 02:31 AM
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-22-2006 12:07 PM
тАО05-22-2006 12:07 PM
Re: Block MAC certain Addresses
ProCurve Switch 2626(config)# lockout-mac
MAC-ADDR Enter MAC address for the 'lockout-mac'
command/parameter.
Don't forget to assign points to posts that have helped you.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-22-2006 12:42 PM
тАО05-22-2006 12:42 PM
Re: Block MAC certain Addresses
ftp://ftp.hp.com/pub/networking/software/Security-Oct2005-59906024-Chap09-Port_Security.pdf
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-22-2006 01:11 PM
тАО05-22-2006 01:11 PM
SolutionProCurve Switch 2626(config)# port-security 1 learn-mode limited-continuous addr
ess-limit 1 action send-alarm
This will let the port learn 1 mac-address only. If it detects a second mac-address, it will send an alarm to your PCM server and add an entry to the switch event log.
Alternatively, you could use 'send-disable' which would also block the port until you 'clear-intrusion-flag'.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-22-2006 03:36 PM
тАО05-22-2006 03:36 PM
Re: Block MAC certain Addresses
If you want only to allow certain MAC per port, then i think what do you need is:
MAC Lockdown which is permanent assignment of a given MAC address to a given port.
the command is:
mac-address [mac address] static VLAN [vid] [port number]
example:
mac-address 001500-3C36D4 static VLAN 2 A6
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-23-2006 01:37 AM
тАО05-23-2006 01:37 AM
Re: Block MAC certain Addresses
ProCurve Switch 2626(config)# port-security 1 learn-mode limited-continuous addr
ess-limit 1 action send-alarm
This will let the port learn 1 mac-address only. If it detects a second mac-address, it will send an alarm to your PCM server and add an entry to the switch event log.
> What if we added our own AP on the network, would that mess up this setup as we would then possibly block our legit AP?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-23-2006 04:41 AM
тАО05-23-2006 04:41 AM
Re: Block MAC certain Addresses
There is something to be said for the user adjusting tool that we keep behind the door.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО05-23-2006 11:17 AM
тАО05-23-2006 11:17 AM
Re: Block MAC certain Addresses
> network, would that mess up this setup as
> we would then possibly block our legit AP?
On your ports with legitimate AP's, you just don't use that command. It is port specific. Also you would not set it on the the switch uplink ports.
As Les said though, if an end-user brought in an AP that was performing NAT it would be harder to detect with this method - you would really need other AP's which deteced the rogue AP's radios. The 420wl and 530wl can do this.