Specifying The Security Violation Action; Setting The Shutdown Timeout - Cisco WS-X6066-SLB-APC - Content Switching Module Software Manual

Catalyst 6000 series software configuration guide
Hide thumbs Also See for WS-X6066-SLB-APC - Content Switching Module:
Table of Contents

Advertisement

Configuring Port Security
This example shows how to clear all MAC addresses from ports 7/5-7:
Console> (enable) clear port security 7/5-7 all
All addresses cleared from secure address list for ports 7/5-7
Console> (enable)

Specifying the Security Violation Action

You can set the port for the following two modes to handle a security violation:
To specify the security violation action to be taken, perform this task in privileged mode:
Task
Specify the violation action on a port.
This example shows how to specify that port 7/7 drop all packets from insecure hosts:
Console> (enable) set port security 7/7 violation restrict
Port security violation on port 7/7 will cause insecure packets to be dropped.
Console> (enable)
If you restrict the number of secure MAC addresses on a port to one and additional hosts attempt to
Note
connect to that port, port security blocks these additional hosts from connecting to that port and to
any other port in the same VLAN for the duration of the VLAN aging time. By default, the VLAN
aging time is five minutes. If a host is blocked from joining a port in the same VLAN as the secured
port, allow the VLAN aging time to expire before you attempt to connect the host to the port again.

Setting the Shutdown Timeout

You can set the time a port remains disabled in case of a security violation. By default, the port is shut
down permanently. The valid range is 10–1440 minutes.
If the time is set to zero, the shutdown is disabled for this port.
When the shutdown timeout expires, the port is reenabled and all port security-related configuration
Note
is maintained.
To set the shutdown timeout, perform this task in privileged mode:
Task
Set the shutdown timeout on a port.
Catalyst 6000 Family Software Configuration Guide—Releases 6.3 and 6.4
35-6
Shutdown—Shuts down the port permanently or for a specified time. Permanent shutdown is the
default mode.
Restrictive—Drops all packets from insecure hosts but remains enabled.
Chapter 35
Command
set port security mod/port violation {shutdown
| restrict}
Command
set port security mod/port shutdown time
Configuring Port Security
78-13315-02

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents