22.05.2017 Views

nx.os.and.cisco.nexus.switching.2nd.edition.1587143046

Nexus Switching 2nd Edition

Nexus Switching 2nd Edition

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

violation; the interface is error-disabled. Reenabling the interface, it retains its port<br />

security configuration, including its secure MAC addresses.<br />

• errdisable: Global configuration comm<strong>and</strong> to configure the device to reenable the<br />

interface automatically if a shutdown occurs, or you can manually reenable the<br />

interface by entering the shutdown <strong>and</strong> no shutdown interface configuration<br />

comm<strong>and</strong>s.<br />

• restrict: After 100 security violations occur, the device disables learning on the<br />

interface <strong>and</strong> drops all ingress traffic from nonsecure MAC addresses. In addition, the<br />

device generates an SNMP notification for each security violation. The address that<br />

triggered the security violation is learned, but any traffic from the address is dropped.<br />

• protect: Prevents further violations from occurring. The address that triggered the<br />

security violation is learned, but any traffic from the address is dropped.<br />

Note<br />

The default security action is to shut down the port on which the security violation<br />

occurs.<br />

Example 5-60 shows how to configure the specific port security violations on interface<br />

Ethernet 1/1.<br />

Example 5-60. Configuring the Specific Port Security Violations on Interface Ethernet<br />

1/1<br />

Click here to view code image<br />

Egypt# conf t<br />

Enter configuration comm<strong>and</strong>s, one per line. End with<br />

CNTL/Z.<br />

Egypt(config)# interface ethernet 1/1<br />

Egypt(config-if)# switchport port-security violation ?<br />

protect Security violation protect mode<br />

restrict Security violation restrict mode<br />

shutdown Security violation shutdown mode<br />

Egypt(config-if)# switchport port-security violation<br />

Example 5-61 shows how to configure a maximum number of MAC addresses on Interface<br />

Ethernet 1/1. Depending on what connects to the interface, such as a virtualized server, you<br />

need to increase the number of MAC addresses, based on the number of virtual machines<br />

<strong>and</strong> virtual interfaces.<br />

Note

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!