Professional Documents
Culture Documents
Port Security & Switchport Redundant
Port Security & Switchport Redundant
Port Security & Switchport Redundant
Port Security
Internet
Network
F
Packet A F Packet B F
f0/4
A Sw1 B
f0/3
F
F
Attacker
C Hyenae
Port Security: Violation Shutdown
A f0/1
errdisable recovery cause psecure-violation
0800.1000.AAAA up errdisable recovery interval 30
0800.1000.BBBB down
Hyenae
interface f0/1 interface f0/1
shutdown switchport mode access
no shutdown switchport port-security
switchport port-security maximum 1
switchport port-security violation shutdown
switchport port-security mac-address 0800.1000.AAAA
Port Security: Violation Restrict
syslog %PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occurred,
caused by MAC address 0800.1000.BBBB on port FastEthernet0/1.
A f0/1
0800.1000.AAAA up
0800.1000.BBBB up
Hyenae
interface f0/1
switchport mode access
switchport port-security
switchport port-security maximum 1
switchport port-security violation restrict
switchport port-security mac-address 0800.1000.AAAA
Port Security: Violation Restrict
Switch# show port-security
Secure Port MaxSecureAddr CurrentAddr SecurityViolation Security Action
(Count) (Count) (Count)
---------------------------------------------------------------------------
F0/1 1 1 12 Restrict
A f0/1
0800.1000.AAAA up
0800.1000.BBBB up
Hyenae
interface f0/1
switchport mode access
switchport port-security
switchport port-security maximum 1
switchport port-security violation restrict
switchport port-security mac-address 0800.1000.AAAA
Port Security: Violation Protect
%PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occurred,
caused by MAC address 0800.1000.BBBB on port FastEthernet0/1.
A f0/1
0800.1000.AAAA up
0800.1000.BBBB up
Hyenae
interface f0/1
switchport mode access
switchport port-security
switchport port-security maximum 1
switchport port-security violation protect
switchport port-security mac-address 0800.1000.AAAA
Port Security
A
Sw1 f0/2 Sw2
interface f0/2
switchport mode access
switchport port-security
switchport port-security maximum 2
switchport port-security violation shutdown
switchport port-security mac-address 0800.1000.AAAA
A
Sw1 f0/2 Sw2
interface f0/2
switchport mode access
switchport port-security
switchport port-security maximum 2
switchport port-security violation shutdown
switchport port-security mac-address sticky
Sw2# clear port-security sticky interface f0/2
Port Security
Sw2# show port-security address
-----------------------------------------------------------------
Vlan Mac Address Type Ports Remaining Age
---- ----------- ---- ----- -------------
1 0800.1000.AAAA SecureSticky F0/2 -
1 0800.1000.BBBB SecureConfigured F0/2 -
A
Sw1 f0/2 Sw2
interface f0/2
switchport mode access
switchport port-security
switchport port-security maximum 2
switchport port-security violation shutdown
switchport port-security mac-address sticky
switchport port-security mac-address 0800.1000.BBBB
Port Security
interface f0/2
switchport mode access
no switchport port-security
no switchport port-security maximum 2
no switchport port-security violation shutdown
no switchport port-security mac-address sticky
no switchport port-security mac-address 0800.1000.BBBB
interface f0/2
switchport mode access
switchport port-security
switchport port-security maximum 2
switchport port-security violation shutdown
switchport port-security mac-address sticky
switchport port-security mac-address 0800.1000.BBBB