实验拓扑图:
实验配置思路:
- 配置安全动态MAC地址
- 配置Sticky MAC地址
- 配置安全静态MAC地址
实验摘要重点命令:
安全动态MAC地址表项
[Huawei]int g0/0/1 //进入接口
[Huawei-GigabitEthernet0/0/1]port-security enable //使能端口安全功能,默认只允许1个,接口down时,表项消失
[Huawei-GigabitEthernet0/0/1]port-security aging-time 30 //配置端口安全老化时间30分钟,默认没有配置即端口不down不小时
[Huawei-GigabitEthernet0/0/1]quit //退出
[Huawei]
Sticky MAC地址表项
[Huawei]int g0/0/2 //进入接口
[Huawei-GigabitEthernet0/0/2]port-security enable //使能端口安全功能
[Huawei-GigabitEthernet0/0/2]port-security mac-address sticky //开启Stick后自动转换成安全MAC
[Huawei-GigabitEthernet0/0/2]port-security max-mac-num 2 //最大数量修改为2,允许两台PC连接
[Huawei-GigabitEthernet0/0/2]quit //退出
[Huawei]
安全静态MAC地址
[Huawei]int g0/0/2 //进入接口
[Huawei-GigabitEthernet0/0/3]port-security enable //使能端口安全功能
[Huawei-GigabitEthernet0/0/3]port-security mac-address sticky //开启Stick后自动转换成安全MAC
[Huawei-GigabitEthernet0/0/3]port-security mac-address sticky 5489-98B7-5543 vlan 1 //绑定静态MAC地址
[Huawei-GigabitEthernet0/0/3]quit //退出
[Huawei]
实验详细配置步骤:
SW1——配置安全动态MAC地址
使能端口安全而未使能Stick MAC功能时转换的MAC地址
[Huawei]int g0/0/1 //进入接口
[Huawei-GigabitEthernet0/0/1]port-security enable //使能端口安全功能,默认只允许1个,接口down时,表项消失
[Huawei-GigabitEthernet0/0/1]port-security aging-time 30 //配置端口安全老化时间30分钟,默认没有配置即端口不down不小时
[Huawei-GigabitEthernet0/0/1]quit //退出
[Huawei]
PC1——ping PC4
PC>ping 192.168.1.4 //ping PC4
Ping 192.168.1.4: 32 data bytes, Press Ctrl_C to break
From 192.168.1.4: bytes=32 seq=1 ttl=128 time=31 ms
From 192.168.1.4: bytes=32 seq=2 ttl=128 time=47 ms
From 192.168.1.4: bytes=32 seq=3 ttl=128 time=32 ms
From 192.168.1.4: bytes=32 seq=4 ttl=128 time=31 ms
From 192.168.1.4: bytes=32 seq=5 ttl=128 time=31 ms //ping 通
--- 192.168.1.4 ping statistics ---
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 31/34/47 ms
PC>
SW1——查看MAC地址表项
查看安全动态的MAC地址
[Huawei]dis mac-address //查看MAC地址表
MAC address table of slot 0:
-------------------------------------------------------------------------------
MAC Address VLAN/ PEVLAN CEVLAN Port Type LSP/LSR-ID
VSI/SI MAC-Tunnel
-------------------------------------------------------------------------------
5489-9801-7cf2 1 - - GE0/0/1 security - //安全动态MAC地址
-------------------------------------------------------------------------------
Total matching items on slot 0 displayed = 1
MAC address table of slot 0:
-------------------------------------------------------------------------------
MAC Address VLAN/ PEVLAN CEVLAN Port Type LSP/LSR-ID
VSI/SI MAC-Tunnel
-------------------------------------------------------------------------------
5489-987c-3773 1 - - GE0/0/4 dynamic 0/-
-------------------------------------------------------------------------------
Total matching items on slot 0 displayed = 1
[Huawei]
SW1——配置Sticky MAC地址
使能端口安全后又同时使能Stick MAC功能后转换的MAC地址
[Huawei]int g0/0/2 //进入接口
[Huawei-GigabitEthernet0/0/2]port-security enable //使能端口安全功能
[Huawei-GigabitEthernet0/0/2]port-security mac-address sticky //开启Stick后自动转换成安全MAC
[Huawei-GigabitEthernet0/0/2]port-security max-mac-num 2 //最大数量修改为2,允许两台PC连接
[Huawei-GigabitEthernet0/0/2]quit //退出
[Huawei]
PC2——ping PC4
修改MAC地址pingPC4,允许两个MAC地址可以ping通PC4,第三个MAC地址ping不同PC4 5489-985c-681a
5489-985c-681b
5489-985c-681c
PC>ping 192.168.1.4 //前两个MAC地址ping PC4
Ping 192.168.1.4: 32 data bytes, Press Ctrl_C to break
From 192.168.1.4: bytes=32 seq=1 ttl=128 time=31 ms
From 192.168.1.4: bytes=32 seq=2 ttl=128 time=31 ms
From 192.168.1.4: bytes=32 seq=3 ttl=128 time=31 ms
From 192.168.1.4: bytes=32 seq=4 ttl=128 time=47 ms
From 192.168.1.4: bytes=32 seq=5 ttl=128 time=32 ms //ping 通
--- 192.168.1.4 ping statistics ---
5 packet(s) transmitted
5 packet(s) received
0.00% packet loss
round-trip min/avg/max = 31/34/47 ms
PC>ping 192.168.1.4 //修改第三个MAC地址ping PC4
Ping 192.168.1.4: 32 data bytes, Press Ctrl_C to break
Request timeout!
Request timeout!
Request timeout!
Request timeout!
Request timeout! //请求超时
--- 192.168.1.4 ping statistics ---
5 packet(s) transmitted
0 packet(s) received
100.00% packet loss
PC>
SW1——查看MAC地址表
查看Sticky MAC地址
[Huawei]dis mac-address //查看MAC地址表
MAC address table of slot 0:
-------------------------------------------------------------------------------
MAC Address VLAN/ PEVLAN CEVLAN Port Type LSP/LSR-ID
VSI/SI MAC-Tunnel
-------------------------------------------------------------------------------
5489-985c-681a 1 - - GE0/0/2 sticky - //Sticky MAC地址
5489-985c-681b 1 - - GE0/0/2 sticky - //Sticky MAC地址
5489-9801-7cf2 1 - - GE0/0/1 security -
-------------------------------------------------------------------------------
Total matching items on slot 0 displayed = 3
MAC address table of slot 0:
-------------------------------------------------------------------------------
MAC Address VLAN/ PEVLAN CEVLAN Port Type LSP/LSR-ID
VSI/SI MAC-Tunnel
-------------------------------------------------------------------------------
5489-987c-3773 1 - - GE0/0/4 dynamic 0/-
-------------------------------------------------------------------------------
Total matching items on slot 0 displayed = 1
[Huawei]
SW1——配置安全静态MAC地址
使能端口安全时手工配置的静态MAC地址
[Huawei]int g0/0/3 //进入接口
[Huawei-GigabitEthernet0/0/3]port-security enable //使能端口安全功能
[Huawei-GigabitEthernet0/0/3]port-security mac-address sticky //开启Stick后自动转换成安全MAC
[Huawei-GigabitEthernet0/0/3]port-security mac-address sticky 5489-98B7-5543 vlan 1 //绑定静态MAC地址
[Huawei-GigabitEthernet0/0/3]quit //退出
[Huawei]
SW1——查看MAC地址表
查看安全静态MAC地址
[Huawei]dis mac-address //查看MAC地址表
MAC address table of slot 0:
-------------------------------------------------------------------------------
MAC Address VLAN/ PEVLAN CEVLAN Port Type LSP/LSR-ID
VSI/SI MAC-Tunnel
-------------------------------------------------------------------------------
5489-98b7-5543 1 - - GE0/0/3 sticky - //安全静态MAC地址
5489-985c-681a 1 - - GE0/0/2 sticky -
5489-985c-681b 1 - - GE0/0/2 sticky -
5489-9801-7cf2 1 - - GE0/0/1 security -
-------------------------------------------------------------------------------
Total matching items on slot 0 displayed = 4
[Huawei]