Configuring Port Security on a Cisco Catalyst Switch
1. Enter global configuration mode.
2. Enter interface configuration mode for the port that you want to secure.
3. Enable basic port security on the interface.
4. Set the maximum number of MAC addresses allowed on this interface.
5. Set the interface security violation mode. The default is shutdown. For mode, select one of these keywords:
• shutdown
• restrict
6. Return to privileged EXEC mode.
7. Verify the entry.
The figure lists the tasks required to configure port security on a Cisco Catalyst switch. The "Enabling Port Security with Cisco IOS Software Commands" table provides a description of the steps and commands required, including additional optional steps.
Enabling Port Security with Cisco IOS Software Commands
|
Step |
Command |
Description |
|
1 |
configure terminal |
This command opens the global configuration mode. |
|
2 |
Switch(config)# interface interface id |
This command enables interface configuration mode. In this mode, the physical interface is configured (for example, gigabitethernet 3/1). |
|
3 |
Switch(config-if)# switchport mode access |
This command sets the interface mode as access. Port security is configured on the access port only. |
|
4 |
Switch(config-if)# switchport port-security |
This command enables port security on the interface. |
|
(Optional) |
Switch(config-if)# switchport port-security maximum value |
This command sets the maximum number of secure MAC addresses for the interface. The range is 1 to 132 for a Cisco Catalyst 2950 Series Switch; 1 to 3072 for a Cisco Catalyst 4500 Series Switch. The default is 1. |
|
(Optional) |
Switch(config-if)# switchport port-security violation {protect | restrict | shutdown} |
This command sets the violation mode. The protect option is platform-dependent or version-dependent. |
|
Step |
Command |
Description |
|
7 |
Switch(config-if)# switchport port-security limit rate invalid-source-mac |
This command sets the rate limit for bad packets. |
|
(Optional) |
Switch(config-if)# switchport port-security mac-address mac_address |
This command enters a secure MAC address for the interface. Use this command to enter the secure MAC addresses. If you configure fewer secure MAC addresses than the maximum, the remaining MAC addresses are dynamically learned. |
|
(Optional) |
Switch(config-if)# switchport port-security mac-address sticky |
This command enables sticky learning on the interface. |
|
10 |
Switch(config-if)# end |
This command returns the console to privileged EXEC mode. |
|
Switch# show port-security address interface interface id Switch# show port-security address |
This command verifies your entries. |
© 2006 Cisco Systems, Inc. Securing LAN and WLAN Devices 3-41
Continue reading here: Port Security Configuration Script
Was this article helpful?