Network World
Saturday, November 22, 2008
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Brad Reese on Cisco

Cisco Subnet

Navigation

How to configure port security on Cisco Catalyst switches

Cisco Catalyst Switch Port Security

How to configure port security on Cisco Catalyst switches that run Cisco IOS system software:

Use the port security feature to restrict input to an interface.

This feature limits and identifies MAC addresses of the workstations that can access the port.

When secure MAC addresses are assigned to a secure port, the port does not forward packets with source addresses outside the group of defined addresses.

If a secure port reaches the maximum number of secure MAC addresses, a security violation occurs when a workstation that attempts to access the port has a MAC address different from any of the identified secure MAC addresses.

To enable port security on an interface, issue the switchport port-security command.

Issue the show port-security command to view port-security settings for an interface or for the switch.

These are the guidelines to configure port security:

A secure port cannot be a trunk port.
A secure port cannot be an 802.1X port.
A secure port cannot belong to an EtherChannel port-channel interface.
A secure port and static MAC address configuration are mutually exclusive.
A secure port cannot be a destination port for Switch Port Analyzer (SPAN).

For step-by-step configuration procedures, refer to these documents:

Cisco Catalyst 2970 Switch

Cisco Catalyst 3550 Switch

Cisco Catalyst 3560 Switch

Cisco Catalyst 3750 Switch

Cisco Catalyst 4500 Switch

Cisco Catalyst 6500 Switch

Contact Brad Reese
http://www.BradReese.Com

Cisco Refurbished Inventory Availability
  

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <i> <b> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <blockquote> <br /> <br> <p>
  • Lines and paragraphs break automatically.
  • You can use BBCode tags in the text.
  • Web page addresses and e-mail addresses turn into links automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

About Brad Reese on Cisco

Brad Reese cofounded BradReese.Com Cisco Refurbished which offers one year warranties on Cisco Refurbished and Cisco Repair.

RSS feed

Contact him.

Brad's blogroll

Brad Reese on Cisco archive.

Cisco Subnet

The opinions expressed in this Weblog are those of the writer and may not represent the opinions of Network World.

Advertisement: