Enabling Port Security - Cisco WS-C4003 - Catalyst 4000 Chassis Switch Software Configuration Manual

Software guide
Table of Contents

Advertisement

Configuring Port Security

Enabling Port Security

Port security is either autoconfigured or enabled manually by specifying a MAC address. If a MAC
address is not specified, the source address from the incoming traffic is autoconfigured and secured, up
to the maximum number of MAC addresses allowed. These autoconfigured MAC Addresses remain
secured for a time, depending upon the aging timer set. The autoconfigured MAC Addresses are cleared
from the port in case of a link-down event.
To enable port security, perform this task in privileged mode:
Task
Step 1
Enable port security on the desired ports. If
desired, specify the secure MAC address.
Step 2
You can add MAC addresses to the list of secure
addresses.
Step 3
Verify the configuration.
This example shows how to enable port security using the learned MAC address on a port and verify the
configuration:
Console> (enable) set port security 2/1 enable
Port 2/1 port security enabled with the learned mac address.
Trunking disabled for Port 2/1 due to Security Mode
Console> (enable) show port 2/1
Port
----- ------------------ ---------- ---------- ------ ------ ----- ------------
2/1
Port
----- -------- ----------------- ----------------- -------- -------- -------
2/1
Port
-------- --------------- --------------
2/1
Port
----- ---------- ---------- ---------- ---------- ---------
2/1
Port
----- ---------- ---------- ---------- ---------- --------- --------- ---------
2/1
Last-Time-Cleared
--------------------------
Fri Jul 10 1998, 17:53:38
This example shows how to enable port security on a port and manually specify the secure MAC address:
Console> (enable) set port security 2/1 enable 00-90-2b-03-34-08
Port 2/1 port security enabled with 00-90-2b-03-34-08 as the secure mac address
Trunking disabled for Port 2/1 due to Security Mode
Console> (enable)
Software Configuration Guide—Catalyst 4000 Family, Catalyst 2948G, Catalyst 2980G, Releases 6.3 and 6.4
16-4
Name
Status
connected
Security Secure-Src-Addr
enabled
00-90-2b-03-34-08 00-90-2b-03-34-08 No
Broadcast-Limit Broadcast-Drop
-
Align-Err
FCS-Err
Xmit-Err
0
0
Single-Col Multi-Coll Late-Coll
0
0
Command
set port security mod_num/port_num enable
[mac_addr]
set port security mod_num/port_num mac_addr
show port [mod_num[/port_num]]
Vlan
Level
Duplex Speed Type
522
normal
Last-Src-Addr
Shutdown Trap
0
Rcv-Err
UnderSize
0
0
Excess-Col Carri-Sen Runts
0
0
Chapter 16
Configuring Port Security
half
100 100BaseTX
IfIndex
disabled 1081
0
Giants
0
0
0
78-12647-02

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 4000 seriesCatalyst 2948gCatalyst 2980g

Table of Contents