Default Port Security Configuration; Port Security Configuration Guidelines; Enabling And Configuring Port Security - Cisco 2950G 24 - Catalyst Switch Software Configuration Manual

Desktop switch
Hide thumbs Also See for 2950G 24 - Catalyst Switch:
Table of Contents

Advertisement

Chapter 18
Configuring Port-Based Traffic Control

Default Port Security Configuration

Table 18-1
Table 18-1 Default Port Security Configuration
Feature
Port security
Maximum number of secure MAC addresses
Violation mode

Port Security Configuration Guidelines

Follow these guidelines when configuring port security:

Enabling and Configuring Port Security

Beginning in privileged EXEC mode, follow these steps to restrict input to an interface by limiting and
identifying MAC addresses of the stations allowed to access the port:
Command
Step 1
configure terminal
Step 2
interface interface-id
Step 3
switchport mode access
Step 4
switchport port-security
78-14982-01
shows the default port security configuration for an interface.
Port security can only be configured on static access ports.
A secure port cannot be a dynamic access port or a trunk port.
A secure port cannot be a destination port for Switch Port Analyzer (SPAN).
A secure port cannot belong to a Fast EtherChannel or Gigabit EtherChannel port group.
A secure port cannot be an 802.1X port.
You cannot configure static secure MAC addresses in the voice VLAN.
When you enable port security on a voice VLAN port, you must set the maximum allowed secure
addresses on the port to at least two. When the port is connected to a Cisco IP phone, the IP phone
requires two MAC addresses: one for the access VLAN and the other for the voice VLAN.
Connecting a PC to the IP phone requires additional MAC addresses.
Default Setting
Disabled on a port
1
Shutdown. The interface is error-disabled when a
security violation occurs. When a secure port is in the
error-disabled state, you can bring it out of this state by
entering the errdisable recovery cause
psecure-violation global configuration command, or
you can manually re-enable it by entering the
shutdown and no shutdown interface configuration
commands.
Purpose
Enter global configuration mode.
Specify the type and number of the physical interface to configure, for
example gigabitethernet0/1, and enter interface configuration mode.
Set the interface mode as access; an interface in the default mode
(dynamic desirable) cannot be configured as a secure port.
Enable port security on the interface.
Catalyst 2950 Desktop Switch Software Configuration Guide
Configuring Port Security
18-7

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 2950

Table of Contents