Ethernet Switching
Highlighted
Ethernet Switching

EX 3400 V15.X ports security on access points

[ Edited ]
Wednesday

For port with single device like printer or end host I would use:

 

These would be the commands to enable port security for EX3400 for more than one MAC Address:
 
set interfaces ge-1/0/4 unit 0 accept-source-mac mac-address 00:00:00:14:25:25
set interfaces ge-1/0/4 unit 0 accept-source-mac mac-address 00:00:00:14:25:26
set interfaces ge-1/0/4 unit 0 accept-source-mac mac-address 00:00:00:14:30:54
set interfaces ge-1/0/4 unit 0 accept-source-mac mac-address 00:00:15:14:30:56
set interfaces ge-1/0/4 unit 0 accept-source-mac mac-address 00:00:15:14:30:57
set interfaces ge-1/0/4 unit 0 family ethernet-switching vlan members MGMT
 
You can configured at interface or vlan level.
set switch-options interface ge-1/0/4.0 interface-mac-limit 2
set switch-options interface ge-1/0/4.0 interface-mac-limit packet-action drop
 
set vlans MGMT switch-options interface ge-1/0/4.0 interface-mac-limit 3
set vlans MGMT switch-options interface ge-1/0/4.0 interface-mac-limit packet-action drop-and-log

 but what about if I want to secure port for access points? This configuration deos not make sence. is there better way? Thank you

1 REPLY 1
Ethernet Switching

Re: EX 3400 V15.X ports security on access points

Wednesday

Not sure what "port security" you want or need for AP connections, but I know for Juniper MIST product, they recommend NOT using MAC Limit for AP connections.

 

FYI