跳到主要內容

Cisco Switch : Port-Security

設定介面安全防護機制,例如禁止員工私帶筆電到公司使用,在Switch介面上綁定Mac-Address

查看有無介面設定Port-Security
SW12#show port-security
Secure Port  MaxSecureAddr  CurrentAddr  SecurityViolation  Security Action
                (Count)       (Count)          (Count)
---------------------------------------------------------------------------
---------------------------------------------------------------------------
Total Addresses in System (excluding one mac per port)     : 0
Max Addresses limit in System (excluding one mac per port) : 1024


SW12#configure terminal
Enter configuration commands, one per line.  End with CNTL/Z.
SW12(config)#interface fastEthernet 0/17
SW12(config-if)#switchport mode access
SW12(config-if)#switchport port-security
SW12(config-if)#switchport port-security maximum 1
SW12(config-if)#switchport port-security mac-address sticky
SW12(config-if)#switchport port-security violation shutdown
SW12(config-if)#^Z

查看有無介面設定Port-Security,可以看到Fa 0/17 設定最多允許一個MAC-Address,已學習到一個,違規的MAC-Address為0,防護機制為直接關掉介面
SW12#show port-security
Secure Port  MaxSecureAddr  CurrentAddr  SecurityViolation  Security Action
                (Count)       (Count)          (Count)
---------------------------------------------------------------------------
     Fa0/17              1            1                  0         Shutdown
---------------------------------------------------------------------------
Total Addresses in System (excluding one mac per port)     : 0
Max Addresses limit in System (excluding one mac per port) : 1024

查看介面Port-Security的Mac-Address狀態,允許的MAC-Address與介面,並且也記錄MAC-Address是如何學習
SW12#show port-security address
          Secure Mac Address Table
-------------------------------------------------------------------
Vlan    Mac Address       Type                Ports   Remaining Age
                                                         (mins)
----    -----------       ----                -----   -------------
   1    0060.6eb0.4d88    SecureSticky        Fa0/17       -
-------------------------------------------------------------------
Total Addresses in System (excluding one mac per port)     : 0
Max Addresses limit in System (excluding one mac per port) : 1024

詳細觀察Fa 017的介面狀態
SW12#show port-security interface fastEthernet 0/17
Port Security              : Enabled
Port Status                : Secure-up
Violation Mode             : Shutdown
Aging Time                 : 0 mins
Aging Type                 : Absolute
SecureStatic Address Aging : Disabled
Maximum MAC Addresses      : 1
Total MAC Addresses        : 1
Configured MAC Addresses   : 0
Sticky MAC Addresses       : 1
Last Source Address        : 0060.6eb0.4d88
Security Violation Count   : 0




SW12(config-if)#switchport port-security violation ?
  protect   Security violation protect mode  合法MAC通過,沒有違規訊息,沒有違規訊息統計
  restrict  Security violation restrict mode  合法MAC通過,有違規訊息,有違規訊息統計  
  shutdown  Security violation shutdown mode 合法MAC不會通過,有違規訊息,有違規訊息統計


。特別注意是被關掉的介面要先shutdown再no shutdown

。清除特定Mac-Address
   clear port-security sticky address 0060.6eb0.4d88

。手動新增MAC-Address
switchport port-security mac-address 0060.6eb0.4d88


留言

這個網誌中的熱門文章

HP A5120 Switch 基本設定

沒用過HP的Switch,指令跟Cisco完全不同,花了一些時間熟悉~ 1.啟動Spanning-Tree,預設沒有開啟 (黑色粗體是我敲的指令) <HP> system-view System View: return to User View with Ctrl+Z. [HP] stp enable [HP] %Apr 26 12:03:59:826 2000 HP MSTP/6/MSTP_ENABLE: STP is now enabled on the device. %Apr 26 12:03:59:918 2000 HP MSTP/6/MSTP_FORWARDING: Instance 0's GigabitEthernet1/0/17 has been set to forwarding state. %Apr 26 12:04:00:068 2000 HP MSTP/6/MSTP_DETECTED_TC: Instance 0's GigabitEthernet1/0/17 detected a topology change. #Apr 26 12:04:00:208 2000 HP MSTP/1/PFWD: hwPortMstiStateForwarding: Instance 0's Port 0.9437200 has been set to forwarding state! 2.DHCP Snooping   (黑色粗體是我敲的指令) 假設我的DHCP Server接在24 Port,其他Port不允許有DHCP Server <HP> system-view System View: return to User View with Ctrl+Z. [HP] dhcp-snooping  DHCP Snooping is enabled. [HP] interface GigabitEthernet 1/0/24 [HP-GigabitEthernet1/0/24 ]dhcp-snooping trust 若是沒有Port 設成dhcp-snooping trust,那麼這台Switch就沒有Client可以從DHCP Serv...

2台 Vigor 2920建立 LAN To LAN VPN (IPsec)

我有兩台Vigor 2920,環境如下: Vigor B 撥出 LAN:192.168.1.0/24 Vigor A 撥入 LAN:172.16.1.0/24 設定如下: Vigor B設定 Vigor A設定 詳細設定請參考官網 http://www.draytek.com/index.php?option=com_k2&view=item&id=2666&Itemid=264&lang=tw

Draytek Vigor 2927

其實心中一直感覺用了十年的Vigor 2920n會掛掉,因為先前也有一台2920n壞過,所以心中也有個底,但突然壞了也真讓人心驚驚! 其實最近都在用Unifi的設備,但考量目前的工作環境與網路需求,就直接更換最新的Vigor 2927,雖然2920n的備份檔不能直接倒回去,不過之前的設定參數都有抓圖下來,所以很快就把設定設回去,這也算是用習慣Draytek的好處~ 下一篇會說明怎麼建立Unifi Dream Machine Pro與Vigor 2927的Site To Site VPN。