Authentication Violation - Cisco Catalyst 4500 Series Command Reference Manual

Cisco ios command reference release ios xe 3.4.0sg and ios 15.1(2)sg
Hide thumbs Also See for Catalyst 4500 Series:
Table of Contents

Advertisement

authentication violation

authentication violation
Use the authentication violation interface configuration command to configure the violation mode:
restrict, shutdown, and replace.
In single-host mode, a security violation is triggered when more than one device are detected on the data
vlan. In multidomain authentication mode, a security violation is triggered when more than one device
are detected on the data or voice VLAN.
Security violation cannot be triggered in multiplehost or multiauthentication mode.
Syntax Description
restrict
shutdown
replace
Defaults
Shut down the port. If the restrict keyword is configured, the port does not shutdown.
Command Modes
Interface configuration
Command History
Release
12.2(50)SG
12.2(54)SG
Usage Guidelines
When a new host is seen in single or multiple- domain modes, replace mode tears down the old session
and authenticates the new host.
Examples
This example shows how to configure violation mode shutdown on a switch:
Switch# configure terminal
Switch(config)# authentication violation shutdown
A port is error-disabled when a security violation triggers on shutdown mode. The following syslog
messages displays:
%AUTHMGR-5-SECURITY_VIOLATION: Security violation on the interface <interface name>, new
MAC address <mac-address> is seen.
%PM-4-ERR_DISABLE: security-violation error detected on <interface name>, putting
<interface name> in err-disable state
Catalyst 4500 Series Switch Cisco IOS Command Reference—Release IOS XE 3.4.0SG and IOS 15.1(2)SG)
2-42
authentication violation { restrict | shutdown | replace}
no authentication violation {restrict | shutdown | replace}
Generates a syslog error when a violation error occurs.
Error disables the [virtual] port on which an unexpected MAC address
occurs.
Replaces the existing host with the new host, instead of errordisabling or
restricting the port.
Modification
Command introduced on the Catalyst 4500 series switch.
Support for replace keyword.
Chapter 2
Cisco IOS Commands for the Catalyst 4500 Series Switches
OL-27596 -01

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents