26-17
Cisco IE 3000 Switch Software Configuration Guide
OL-13018-03
Chapter 26 Configuring Port-Based Traffic Control
Configuring Port Security
This example shows how to enable sticky port security on a port, to manually configure MAC addresses
for data VLAN and voice VLAN, and to set the total maximum number of secure addresses to 20 (10 for
data VLAN and 10 for voice VLAN).
Switch(config)#
interface FastEthernet1/1
Switch(config-if)#
switchport access vlan 21
Switch(config-if)#
switchport mode access
Switch(config-if)#
switchport voice vlan 22
Switch(config-if)#
switchport port-security
Switch(config-if)#
switchport port-security maximum 20
Switch(config-if)#
switchport port-security violation restrict
Switch(config-if)#
switchport port-security mac-address sticky
Switch(config-if)#
switchport port-security mac-address sticky 0000.0000.0002
Switch(config-if)#
switchport port-security mac-address 0000.0000.0003
Switch(config-if)#
switchport port-security mac-address sticky 0000.0000.0001 vlan voice
Switch(config-if)#
switchport port-security mac-address 0000.0000.0004 vlan voice
Switch(config-if)#
switchport port-security maximum 10 vlan access
Switch(config-if)#
switchport port-security maximum 10 vlan voice
Enabling and Configuring Port Security Aging
You can use port security aging to set the aging time for all secure addresses on a port. Two types of
aging are supported per port:
•
Absolute—The secure addresses on the port are deleted after the specified aging time.
•
Inactivity—The secure addresses on the port are deleted only if the secure addresses are inactive for
the specified aging time.
Use this feature to remove and add devices on a secure port without manually deleting the existing secure
MAC addresses and to still limit the number of secure addresses on a port. You can enable or disable the
aging of secure addresses on a per-port basis.
Beginning in privileged EXEC mode, follow these steps to configure port security aging:
Command
Purpose
Step 1
configure terminal
Enter global configuration mode.
Step 2
interface
interface-id
Specify the interface to be configured, and enter interface
configuration mode.
Содержание IE 3000
Страница 36: ...xxxiv Cisco IE 3000 Switch Software Configuration Guide OL 13018 03 Preface ...
Страница 784: ...39 20 Cisco IE 3000 Switch Software Configuration Guide OL 13018 03 Chapter 39 Troubleshooting Troubleshooting Tables ...
Страница 874: ...Index IN 42 Cisco IE 3000 Switch Software Configuration Guide OL 13018 03 ...