Default Port Security Configuration; Port Security Configuration Guidelines - Cisco ME 3400G-2CS - Ethernet Access Switch Software Configuration Manual

Ethernet access switch
Hide thumbs Also See for ME 3400G-2CS - Ethernet Access Switch:
Table of Contents

Advertisement

Configuring Port Security
Table 21-1
security.
Table 21-1
Security Violation Mode Actions
Traffic is
Violation Mode
forwarded
protect
No
restrict
No
shutdown
No
1. Packets with unknown source addresses are dropped until you remove a sufficient number of secure MAC addresses.
2. The switch returns an error message if you manually configure an address that would cause a security violation.

Default Port Security Configuration

Table 21-2
Table 21-2
Feature
Port security
Sticky address learning
Maximum number of secure
MAC addresses per port
Violation mode
Port security aging

Port Security Configuration Guidelines

Follow these guidelines when configuring port security:
Cisco ME 3400 Ethernet Access Switch Software Configuration Guide
21-10
shutdown—a port security violation causes the interface to become error-disabled and to shut down
immediately, and the port LED turns off. An SNMP trap is sent, a syslog message is logged, and the
violation counter increments. When a secure port is in the error-disabled state, you can bring it out
of this state by entering the errdisable recovery cause psecure-violation global configuration
command, or you can manually re-enable it by entering the shutdown and no shut down interface
configuration commands. This is the default mode.
shows the violation mode and the actions taken when you configure an interface for port
Sends SNMP
1
trap
No
Yes
Yes
shows the default port security configuration for an interface.
Default Port Security Configuration
Port security can only be configured on static access ports or trunk ports. A secure port cannot be a
dynamic access port.
A secure port cannot be a destination port for Switched Port Analyzer (SPAN).
A secure port cannot belong to a Fast EtherChannel or a Gigabit EtherChannel port group.
A secure port cannot be a private-VLAN port.
Sends syslog
Displays error
message
message
No
No
Yes
No
Yes
No
Default Setting
Disabled on a port.
Disabled.
1.
Shutdown. The port shuts down when the maximum number of
secure MAC addresses is exceeded.
Disabled. Aging time is 0.
Static aging is disabled.
Type is absolute.
Chapter 21
Configuring Port-Based Traffic Control
Violation
counter
2
increments
No
Yes
Yes
Shuts down port
No
No
Yes
78-17058-01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents