Setting The Security Violation Action - Cisco WS-C2948G-GE-TX Configuration Manual

Catalyst 4500 series switch
Table of Contents

Advertisement

Configuring Port Security on the Switch
To set the SNMP trap MAC address notification, perform this task in privileged mode:
Task
Set the SNMP traps on the system.
This example shows how to enable MAC address notification globally, enable notification of added and
removed MAC addresses, and set the interval time between notifications:
Console> (enable) set cam notification enable
MAC address change detection globally enabled
Be sure to specify which ports are to detect MAC address changes
with the 'set cam notification [added|removed] enable <m/p> command.
SNMP traps will be sent if 'set snmp trap enable macnotification' has been set.
Console> (enable) set cam notification historysize 300
MAC address change history log size set to 300 entries
Console> (enable) set cam notification added enable 3/1-4
MAC address change notifications for added addresses are
enabled on port(s) 3/1-4
Console> (enable) set cam notification removed enable 3/3-6
MAC address change notifications for removed addresses are
enabled on port(s) 3/3-6
Console> (enable) set cam notification interval 10
MAC address change notification interval set to 10 seconds
Console> (enable) show cam notification all
MAC address change detection enabled
CAM notification interval = 10 second(s).
MAC address change history log size = 300
MAC addresses added = 3
MAC addresses removed = 5
MAC addresses added overflowed = 0
MAC addresses removed overflowed = 0
MAC address SNMP traps generated = 0
Console> (enable) set snmp trap enable macnotification
SNMP MAC notification trap enabled.
Console> (enable)

Setting the Security Violation Action

You can set a port to the following two modes to handle a security violation:
To set the security violation action to be taken, perform this task in privileged mode:
Task
Set the security violation action on a port. set port security mod_num/port_num violation
Catalyst 4500 Series, Catalyst 2948G, Catalyst 2948G-GE-TX, and Catalyst 2980G Switches Software Configuration Guide—Release 8.2GLX
16-8
Shutdown—Shuts down the port permanently or for a specified time. Permanent shutdown is the
default mode.
Restrict—Drops all packets from insecure hosts, but remains enabled.
Command
set snmp trap enable macnotification
Command
{shutdown | restrict}
Chapter 16
Configuring Port Security
78-15908-01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents