C
ONFIGURING
P
ORT
S
ECURITY
2-45
CLI
– This example enables SSH, sets the authentication parameters, and
displays the current configuration. It shows that the administrator has
made a connection via SHH, and then disables this connection.
Configuring Port Security
Port security is a feature that allows you to configure a switch port with
one or more device MAC addresses that are authorized to access the
network through that port.
When port security is enabled on a port, the switch stops learning new
MAC addresses on the specified port when it has reached a configured
maximum number. Only incoming traffic with source addresses already
stored in the dynamic or static address table will be accepted as authorized
to access the network through that port.
To use port security, specify a maximum number of addresses to allow on
the port and then let the switch dynamically learn the <source MAC
address, VLAN> pair for frames received on the port. When the port has
reached the maximum number of MAC addresses the selected port will
stop learning. The MAC addresses already in the address table will be
retained and will not age out. Any other device that attempts to use the
port will be prevented from accessing the switch.
Console(config)#ip ssh server
3-49
Console(config)#ip ssh timeout 100
3-50
Console(config)#ip ssh authentication-retries 5
3-50
Console(config)#
Console#show ip ssh
3-51
Information of secure shell
SSH status: enable
SSH authentication timeout: 100
SSH authentication retries: 5
Console#show ssh
3-52
Information of secure shell
Session Username Version Encrypt method Negotiation state
------- -------- ------- -------------- -----------------
0 admin 1.5 cipher-3des session-started
Console#disconnect ssh 0
3-51
Console#
Содержание 6724AL2
Страница 2: ......
Страница 404: ...COMMAND LINE INTERFACE 3 216 ...
Страница 406: ...TROUBLESHOOTING A 2 ...
Страница 418: ...GLOSSARY Glossary 8 ...
Страница 422: ...INDEX Index 4 ...
Страница 423: ......