Configuring Port Security on a Cisco Catalyst Switch

1. Enter global configuration mode.

2. Enter interface configuration mode for the port that you want to secure.

3. Enable basic port security on the interface.

4. Set the maximum number of MAC addresses allowed on this interface.

5. Set the interface security violation mode. The default is shutdown. For mode, select one of these keywords:

• shutdown

• restrict

6. Return to privileged EXEC mode.

7. Verify the entry.

The figure lists the tasks required to configure port security on a Cisco Catalyst switch. The "Enabling Port Security with Cisco IOS Software Commands" table provides a description of the steps and commands required, including additional optional steps.

Enabling Port Security with Cisco IOS Software Commands

Step

Command

Description

1

configure terminal

This command opens the global configuration mode.

2

Switch(config)# interface interface id

This command enables interface configuration mode. In this mode, the physical interface is configured (for example, gigabitethernet 3/1).

3

Switch(config-if)# switchport mode access

This command sets the interface mode as access. Port security is configured on the access port only.

4

Switch(config-if)# switchport port-security

This command enables port security on the interface.

(Optional)

Switch(config-if)# switchport port-security maximum value

This command sets the maximum number of secure MAC addresses for the interface. The range is 1 to 132 for a Cisco Catalyst 2950 Series Switch; 1 to 3072 for a Cisco Catalyst 4500 Series Switch. The default is 1.

(Optional)

Switch(config-if)# switchport port-security violation {protect | restrict | shutdown}

This command sets the violation mode.

The protect option is platform-dependent or version-dependent.

3-40 Securing Cisco Network Devices (SND) v2.0 © 2006 Cisco Systems, Inc.

Readers' Questions

  • abaalom
    How to enable port on cisco switch?
    10 months ago
    1. Log into the switch by entering the console command "enable."
    2. Enter the command "configure terminal," which will open the configuration mode of the switch.
    3. Next, enter the command "interface {portnumber}", which will open the interface configuration of the specified port.
    4. To enable the port, enter the command "no shutdown".
    5. Finally, exit the configuration mode by entering the command "end" or "exit", and save the configuration by entering the command "write memory".
    • MANDY
      Which of the following is required when configuring port security with sticky learning?
      10 months ago
    • A. MAC address B. Maximum number of secure addresses C. Aging time D. Secure MAC address action A. MAC address

      Step

      Command

      Description

      7

      Switch(config-if)# switchport port-security limit rate invalid-source-mac

      This command sets the rate limit for bad packets.

      (Optional)

      Switch(config-if)# switchport port-security mac-address mac_address

      This command enters a secure MAC address for the interface. Use this command to enter the secure MAC addresses. If you configure fewer secure MAC addresses than the maximum, the remaining MAC addresses are dynamically learned.

      (Optional)

      Switch(config-if)# switchport port-security mac-address sticky

      This command enables sticky learning on the interface.

      10

      Switch(config-if)# end

      This command returns the console to privileged EXEC mode.

      Switch# show port-security address interface interface id

      Switch# show port-security address

      This command verifies your entries.

      © 2006 Cisco Systems, Inc. Securing LAN and WLAN Devices 3-41

      Continue reading here: Port Security Configuration Script

      Was this article helpful?

      0 0