Port MAC Security

Port MAC Security is a port-level access control feature that enhances network security by allowing only authorized devices to communicate through a network switch port.

Feature Overview

Port MAC Security functionality allows you to specify which source MAC addresses are permitted on a given port. It works by maintaining a list of permitted source MAC addresses for each port. When a device attempts to send traffic through a port, the switch checks the source MAC address against this list. If the MAC address is on the allowed list, the traffic is forwarded; if not, the switch blocks the traffic by using a DROP action. This mechanism helps prevent unauthorized devices from gaining access to the network, thereby reducing security risks such as MAC spoofing or unauthorized access.

Starting from SmartZone version 7.1.1, you can configure Port MAC Security directly through the SZ Web UI, enabling tighter security at the network edge while maintaining operational efficiency.

Requirements

The following requirements must be met to enable and configure the Port MAC Security functionality using the controller:

  • RUCKUS ICX switches must be running FastIron firmware version 10.0.20b_cd1 or later.
  • SmartZone must be running version 7.1.1 or later.

Considerations

Consider the following when configuring and using this feature:

  • Each Port MAC Security configuration is uniquely associated with a single port in a one-to-one relationship.
  • When this configuration is saved on the controller, it automatically pushes the required commands to the ICX switch to apply Port MAC Security to the designated port.

Limitations

Following are the limitations of this feature.

  • IPv6-only SmartZone controllers do not support configuring Port MAC Security.
  • The number of allowed MAC addresses for Port MAC Security ranges from 1 through 8256.
  • An ICX switch shares a global resource across all ports; that global resource can contain a maximum of 8192 MAC address mappings. Each port also has a local resource that can contain a maximum of 64 MAC address mappings. Take these numbers into consideration when configuring the maximum number of MAC addresses to be allowed per port. For example, if one port is configured with the maximum value of 8256 for Port MAC Security, that consumes the entire allotment of 8192 global resources and the 64 port-specific local resources, leaving the remaining ports with only their 64 local resources available for Port MAC Security configuration. Any port configuration that exceeds the available resource allotment will result in an error message and the configuration will be rejected.
  • A MAC address may be assigned to only one switch port. Attempting to assign the same MAC address to another port will result in an error message and the configuration will be rejected.

Best Practices

Follow these best practices when using this feature.

  • Begin by maintaining a well-documented list of authorized MAC addresses for each port.
  • Avoid configuring the maximum allowed limit (8256) on multiple ports.

Prerequisites

This feature has no prerequisites to feature enablement or usage.