set maclock firstarrival
17-58 Security Configuration
Mode
Switchcommand,read‐write.
Example
ThisexampleshowshowtoresetthenumberofallowablestaticMACsonfe.2.3:
D2(rw)->clear maclock static fe.2.3
set maclock firstarrival
UsethiscommandtorestrictMAClockingonaporttoamaximumnumberofendstation
addressesfirstconnectedtothatport.
Syntax
set maclock firstarrival port-string value
Parameters
Defaults
None.
Mode
Switchcommand,read‐write.
Usage
Themaclockfirstarrivalcountresetswhenthelinkgoesdown.Thisfeatureisbeneficialifyou
haveroamingusers—thefirstarrivalcount willbereseteverytimeausermovestoanotherport,
butwillstillprotectagainstconnectingmultipledevicesonasingleportand willprotectagainst
MAC
addressspoofing.
Example
ThisexampleshowshowtorestrictMAClockingto6MACaddressesonfe.2.3:
D2(su)->set maclock firstarrival fe.2.3 6
port‐string SpecifiestheportonwhichtolimitMAClocking.Foradetailed
descriptionofpossibleport‐stringvalues,referto“PortStringSyntaxUsed
intheCLI”onpage 6‐1.
value Specif iesthenumberoffirstarrivalendstationMACaddressestobe
allowedconnectionstotheport.Valid
valuesare0to600.
Note: Setting a port’s first arrival limit to 0 does not deny the first MAC address learned on the port
from passing traffic.