Configuring The Port Security Rate Limiter - Cisco 7604 Configuration Manual

Ios software configuration guide
Hide thumbs Also See for 7604:
Table of Contents

Advertisement

Chapter 47
Configuring Port Security
When configuring port security violation modes, note the following information:
Note
This example shows how to configure the protect security violation mode on Fast Ethernet port 5/12:
Router# configure terminal
Enter configuration commands, one per line.
Router(config)# interface fastethernet 3/12
Router(config-if)# switchport port-security violation protect
Router(config-if)# do show port-security interface fastethernet 5/12 | include Protect
Violation Mode
This example shows how to configure the restrict security violation mode on Fast Ethernet port 5/12:
Router# configure terminal
Enter configuration commands, one per line.
Router(config)# interface fastethernet 3/12
Router(config-if)# switchport port-security violation restrict
Router(config-if)# do show port-security interface fastethernet 5/12 | include Restrict
Violation Mode

Configuring the Port Security Rate Limiter

Note
OL-4266-08
protect—Drops packets with unknown source addresses until you remove a sufficient number of
secure MAC addresses to drop below the maximum value.
restrict—Drops packets with unknown source addresses until you remove a sufficient number of
secure MAC addresses to drop below the maximum value and causes the SecurityViolation counter
to increment.
shutdown—Puts the interface into the error-disabled state immediately and sends an SNMP trap
notification.
To bring a secure port out of the error-disabled state, enter the errdisable recovery cause
violation_mode global configuration command, or you can manually reenable it by entering the
shutdown and no shut down interface configuration commands.
To protect the CPU against overutilization, when you configure the protect or restrict violation
modes, configure the packet drop rate limiter (see the
section on page
47-7).
The PFC2 does not support the port security rate limiter.
The truncated switching mode does not support the port security rate limiter.
Cisco 7600 Series Router Cisco IOS Software Configuration Guide, Release 12.2SX
End with CNTL/Z.
: Protect
End with CNTL/Z.
: Restrict
Configuring Port Security
"Configuring the Port Security Rate Limiter"
47-7

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

761376067609-s7600 series

Table of Contents