Console encryption, port security configuration

Console encryption, port security configuration
Configuration S1:
<the Huawei> // Use the undo Monitor Terminal Close message alert
Info: Current Monitor Terminal IS OFF.
<The Huawei> // System View-system view
the Enter System View, View User return the Z with the Ctrl +.
[The Huawei] Sysname S1 // designated Sl
[Sl] User-interface console 0 // enter console
[S1-ui-console0] authentication -mode password // set the authentication mode
[S1-ui-console0] set authentication password cipher hcip // arranged densely text password
[S1-ui-console0] idle -timeout 5 // idle time of 5 minutes

Authentication modes are:
None ----> No authentication
Password ----> password authentication ----> clear text (simple), the ciphertext (the cipher keyword)
AAA ----> user and password authentication

Setup is complete! ! !
Test:
Console encryption, port security configuration
Set the port security:
[Sl] int E0 / 0 /. 1 // access port E0 / 0 /. 1
[S1-Ethernet0 / 0/1] // Port-Open Security enable port security
[S1-Ethernet0 / 0/1 ] port-security mac-address sticky // applicators arranged dynamic binding
[S1-Ethernet0 / 0/1 ] port-security max-mac-num 1 // a configuration can only bind the MAC
[Sl] int E0 / 0/2 // access port E0 / 0/2
[Sl-Ethernet0 / 0/2] // port-open security enable port security
[S1-Ethernet0 / 0/2 ] port-security mac-address sticky // dynamic configuration adhesive binding
[S1-Ethernet0 / 0/2 ] port-security max-mac-num 1 // configuration can only bind one MAC

Port-Security, there are three kinds of
security dynamics (security Dynamic) ----> After the device restarts need to re-learn.
Manual configuration (security configured) ----> manual configuration workload.
Security paste (security sticky) ----> After the device is restarted, not lost.

Check the switch MAC address table: first carried out since the beginning of the ping command MAC represents an empty front view
Console encryption, port security configuration
switch works:
---> initialize
---> Learning
---> Unknown broadcast data frame
---> in response to the receiving end
- -> unicast communication

Guess you like

Origin blog.51cto.com/13657043/2419821