20.01.2013 Views

CCNA 3 Labs and Study Guide - BINARYBB.INFO – @jagalbraith

CCNA 3 Labs and Study Guide - BINARYBB.INFO – @jagalbraith

CCNA 3 Labs and Study Guide - BINARYBB.INFO – @jagalbraith

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Step 3. What comm<strong>and</strong>s can you use to verify port security?<br />

show port-security<br />

show port-security address<br />

show port-security interface fa0/4<br />

ALSW#show port-security<br />

Secure Port MaxSecureAddr CurrentAddr SecurityViolation Security Action<br />

(Count) (Count) (Count)<br />

—————————————————————————————————————-<br />

Fa0/4 1 1 0<br />

Shutdown<br />

—————————————————————————————————————-<br />

Total Addresses in System (excluding one mac per port) : 0<br />

Max Addresses limit in System (excluding one mac per port) : 1024<br />

ALSW#show port-security address<br />

Secure Mac Address Table<br />

—————————————————————————————————-<br />

Vlan Mac Address Type Ports Remaining Age<br />

(mins)<br />

—— —————- —— ——- ——————-<br />

1 00b0.d092.8057 SecureSticky Fa0/4 -<br />

—————————————————————————————————-<br />

Total Addresses in System (excluding one mac per port) : 0<br />

Max Addresses limit in System (excluding one mac per port) : 1024<br />

ALSW#show port-security interface fa0/4<br />

Port Security : Enabled<br />

Port Status : Secure-up<br />

Violation Mode : Shutdown<br />

Aging Time : 0 mins<br />

Aging Type : Absolute<br />

SecureStatic Address Aging : Disabled<br />

Maximum MAC Addresses : 1<br />

Total MAC Addresses : 1<br />

Configured MAC Addresses : 0<br />

Sticky MAC Addresses : 1<br />

Last Source Address : 00b0.d092.8057<br />

Security Violation Count : 0<br />

Chapter 6: Catalyst Switch Configuration 311<br />

Step 4. Test port security by removing host A <strong>and</strong> attaching host B to the FastEthernet 0/4 port. The<br />

port LED should turn from green to OFF. If it does not, send a frame to ALSW by pinging its<br />

VLAN interface from host B. Watch for console messages from the switch. You should see the<br />

following:<br />

00:06:03: %PM-4-ERR_DISABLE: psecure-violation error detected on Fa0/4, putting<br />

Fa0/4 in err-disable state<br />

00:06:03: %PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occurred,<br />

caused by MAC address 00b0.d092.80c3 on port FastEthernet0/4.<br />

00:06:04: %LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/4,<br />

changed state to down<br />

00:06:05: %LINK-3-UPDOWN: Interface FastEthernet0/4, changed state to down

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!