56-2
Catalyst 4500 Series Switch, Cisco IOS Software Configuration Guide - Cisco IOS XE 3.9.xE and IOS 15.2(5)Ex
Chapter 56 Configuring Auto Security
Configuring Auto Security
AS configures trunk or DHCP server-facing port(s) as trusted (with the
ip dhcp-snooping trust
command).
Dynamic ARP Inspection
AS enables this feature globally on all VLANs present on the switch (with the
ip arp inspection vlan
vlanid
) command.
AS configures the trunk port as trusted (with the
ip arp inspection trust
command).
Port Security
AS enables this feature on all the switch’s access ports (with the
switchport port-security
command).]
Configuring Auto Security
Enabling auto security globally
To enable auto security globally, perform this task:
This example shows how to enable auto security globally:
Switch(config)#
auto security
Switch#
show running-config
|
i security
auto security
Relevant baseline security feature CLI as shown in the output of the show auto security command is
applied on or removed from access and trunk ports.
Disabling auto security globally
To disable auto security globally, perform this task:
Command
Purpose
Step 1
Switch#
configure terminal
Enters global configuration mode.
Step 2
Switch(config)#
auto security
Enables auto security globally.
Step 3
Switch(config)#
end
Returns to privileged EXEC mode.
Step 4
Switch#
show running-config | i security
(Optional) Saves your entries in the configuration file.
Command
Purpose
Step 1
Switch#
configure terminal
Enters global configuration mode.
Step 2
Switch(config)#
no auto security
Dis-enables auto security globally.
Step 3
Switch(config)#
end
Returns to privileged EXEC mode.
Step 4
Switch#
show running-config | isecurity
(Optional) Saves your entries in the configuration file.
Summary of Contents for Catalyst 4500 Series
Page 2: ......
Page 4: ......
Page 2086: ...Index IN 46 Software Configuration Guide Release IOS XE 3 9 0E and IOS 15 2 5 E ...