27 05+Preventing+Unauthorised+Devices+With+Port+Security
27 05+Preventing+Unauthorised+Devices+With+Port+Security
27 05+Preventing+Unauthorised+Devices+With+Port+Security
SW1(config)#int f0/2
SW1(config-if)#shutdown
Port Security
f0/2
PC1 Allowed MAC: 1.1.1
MAC: 1.1.1
Port Security
f0/2
PC1 Allowed MAC: 1.1.1
MAC: 1.1.1
Port Security
f0/2
PC2 Allowed MAC: 1.1.1
MAC: 2.2.2
Port Security
It is easy to spoof a MAC address, so locking ports down to a specific
host is not usually Port Security’s main role in production networks
Port Security can also configure individual switch ports to allow only a
specified number of source MAC addresses to send traffic in to the
port
It can learn connected MAC addresses
f0/2
PC1 Allow 1 MAC address
MAC: 1.1.1 Learned MAC: 1.1.1
Port Security
This is useful to prevent users from adding Wireless Access Points or
other shared devices
PC2
MAC: 2.2.2
f0/2
Allow 1 MAC address
Learned MAC: 1.1.1
PC1
MAC: 1.1.1
Port Security Configuration
SW1(config)#int f0/2
SW1(config-if)#switchport port-security
Port Security Default Behaviour
You can bring error disabled ports back into service automatically after
they have been disabled for a configurable period of time (in seconds)