Setting The Shutdown Time; Disabling Port Security - Cisco WS-C2948G-GE-TX Configuration Manual

Catalyst 4500 series switch
Table of Contents

Advertisement

Chapter 16
Configuring Port Security
This example shows how to set the port to drop all packets that are coming in on the port from insecure
hosts:
Console> (enable) set port security 4/7 violation restrict
Port security violation on port 4/7 will cause insecure packets to be dropped.
Console> (enable)
If you restrict the number of secure MAC addresses on a port to one, and additional hosts attempt to
Note
connect to that port, port security prevents these additional hosts from being connected to that port and
to any other port in the same VLAN for the duration of the VLAN aging time. By default, the VLAN
aging time is 5 minutes. If a host is blocked from joining a port in the same VLAN as the secured port,
allow the VLAN aging time to expire before you attempt to connect the host to the port again.

Setting the Shutdown Time

You can specify how long a port is to remain disabled in the event of a security violation. By default, the
port is shut down permanently. The valid range is from 1–1440 minutes.
If you set the time to zero, the shutdown is disabled for this port.
Note
When the shutdown timeout expires, the port is reenabled and all port security-related configuration is
maintained.
To set the shutdown timeout, perform this task in privileged mode:
Task
Set the shutdown timeout on a port.
This example shows how to set the shutdown time to 600 minutes on port 4/7:
Console> (enable) set port security 4/7 shutdown 600
Secure address shutdown time set to 600 minutes for port 4/7.
Console> (enable)

Disabling Port Security

To disable port security, perform this task in privileged mode:
Task
Step 1
Disable port security on the desired ports.
Step 2
Verify the configuration.
Catalyst 4500 Series, Catalyst 2948G, Catalyst 2948G-GE-TX, and Catalyst 2980G Switches Software Configuration Guide—Release 8.2GLX
78-15908-01
Configuring Port Security on the Switch
Command
set port security mod_num/port_num shutdown
time
Command
set port security mod_num/port_num disable
show port security [mod_num/port_num]
16-9

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents