Skip to main content

CCNA Recap: Port Security



Trunk ports and Etherchannel ports are not eligible for Port Security.
Why?

Etherchannel ports are bundled logically to look like one link with larger capacity than a single link.

Trunk ports carry all traffic.

switchport mode access
switchport port-security



Port security
  • does not care where frames come from (local device or other switches)
  • Watch incoming frames, keeps list of source MACs & counter of source macs

Sticky Secure Mac Addresses
  • Port security learns mac of each port and stores them so you don’t have to put in everyone by hand.
Because it's a switch  - Layer 2 - It's all about MAC Addresses.




show port-security [interface] #

Secure Shutdown
  • interface has been disabled because of port-security detecting a MAC address it doesn't recognize.

Protect
  • discards traffic

Restrict
  • Discards Traffic
  • Sends log / SNMP messages (161/162)

Err-Disabled Shutdown
  • discards traffic
  • Sends log / snmp messages
  • +1 violation counter per frame
  • disables interface and discards all traffic
  • default setting

Sticky

  • When someone plugs into the port, the switch remembers it. If someone else tries to, the port doesn't work.
Further Reading;

Switchport Port Security Explained

EMPLOYERS: This is me putting new skills into practice.

Comments

Popular posts from this blog

What Do You Need? [AKA; List of Offered Services / My Next Role] (2020)

I am a trusted outsourced remote consultant for your company.   I enjoy having the flexibility to take on temporary projects from time to time! I start at part-time, temp work for now. If we like each other, we can renegotiate. If anything sounds weird, out there, or unusual - Feel free to e-mail me .  3 Services Offered Writing :      You want to pay me to write more of *waves hand* this blog? I am game .     I write B2C e-mails going out to over 280 people weekly. [ Example Job Description ]        Auditing :        Something doesn't work on your page or in your app. I can find it, or you can lose business. [ Here ] [ Example Job Description ]   I really enjoy testing apps and webpage concepts! I have an iPhone and Android phones ready. Technical: Still as-needed, always remote, contract, or temporary. IT Operations Tech [ Example Job Description ]     Hardware and SaaS support.     Cisco routing and switching (Networking). CCNA, A+, Sec+, Azure certified WORKING ON: Junos

Portfolio of UX/Product Feedback [Vol. 1]

I browse websites and apps, while making note of things I find frustrating for end users. You have probably been linked here from a form or my resume. If you have any questions about what I'm looking for in a role, click here .   This post is not to shame, but to point out errors and hopefully make my talent for finding and documenting such mistakes clear to someone hiring. Contents: Instances where I offer constructive feedback on someone's website, logo, or app. Actions that were taken by the developers or artists.  I'm glad you want your webpages to be the best they can be with my help; If you need your sites audited, e-mail me . Latest Update -  November 20th, 2020.   Vol. 2 is here .

Contactless Tech’s Role in the New Guest Experience ft. Intelity and The George

 Contactless hospitality technology is growing. You want to get away, and you'll be damned if a little thing like a deadly virus will stop you! But you still don't want to touch things. Ew. During the chat between INTELITY CEO Robert Stevenson and THE GEORGE Director of Operations Kerrie Hunter, you’ll learn how the historic boutique hotel has adapted a mobile-first guest experience in the wake of COVID-19—and how they see contactless technology affecting the future of hospitality. I don't remember how I found INTELITY (probably hoping to score a position with them), but I liked them enough to stay on the e-mail lists.