Switch(config)#interface fastEthernet 0/1 Switch(config-if)#switchport mode access (當(dāng)端口連接是主機(jī)時(shí),接入鏈路) Switch(config-if)#switchport port-security (啟動(dòng)端口安全) Switch(config-if)#switchport port-security mac-address 00E0.A342.20E6 (綁定一個(gè)MAC地址,默認(rèn)只能綁定一個(gè)MAC地址) Switch(config-if)#switchport port-security violation ? protect Security violation protect mode (不轉(zhuǎn)發(fā)數(shù)據(jù)) restrict Security violation restrict mode (不轉(zhuǎn)發(fā)數(shù)據(jù),上報(bào)網(wǎng)管平臺(tái)) shutdown Security violation shutdown mode (關(guān)閉接口,并上報(bào)網(wǎng)管平臺(tái)) Switch(config-if)#switchport port-security violation shutdown |
Switch(config)#errdisable recovery interval ? <30-86400> timer-interval(sec) 可以調(diào)整在30-86400秒,缺省是300秒。 |
Switch#udld reset No ports are disabled by UDLD. 同時(shí),接口在被置為err-disable的時(shí)候,通常有一系列的日志產(chǎn)生,如下: *Mar 15 15:47:19.984: %SPANTREE-2-BLOCK_BPDUGUARD: Received BPDU on port FastEthernet0/47 with BPDU Guard enabled. Disabling port. sw1# *Mar 15 15:47:19.984: %PM-4-ERR_DISABLE: bpduguard error detected on Fa0/47, putting Fa0/47 in err-disable state sw1# *Mar 15 15:47:21.996: %LINK-3-UPDOWN: Interface FastEthernet0/47, changed state to down |
Switch#show mac-address-table Mac Address Table ------------------------------------------- Vlan Mac Address Type Ports ---- ----------- -------- ----- 1 0009.7c11.89e7 DYNAMIC Fa0/3 而這一條是動(dòng)態(tài)學(xué)習(xí)到的 1 000a.41a9.79b0 DYNAMIC Fa0/2 這條也是動(dòng)態(tài)學(xué)習(xí)到的 1 00e0.a342.20e6 STATIC Fa0/1 這一個(gè)端口的MAC地址我們可以看見是靜態(tài)指定的。 Switch# |
Switch(config)#interface fastEthernet 0/1 Switch(config-if)#switchport port-security violation restrict |
SW1(config)#interface fastethernet 0/1 Switch(config-if)#Switch port-security maximum 3 設(shè)置綁定多少個(gè)MAC地址,而這里我設(shè)置的是3條 Switch(config-if)#Switchport port-security max-address *** 第一條的MAC地址。 Switch(config-if)#Switchport port-security mac-address *** 第二條的MAC地址。 Switch(config-if)#Switchport port-security max-address *** 第三條的MAC地址。 |
SW1(config)#interface fastethernet 0/1 Switch(config-if)#Switch port-security maximum 3 設(shè)置綁定多少個(gè)MAC地址,而這里我設(shè)置的是3條 Switch(config-if)#switchport port-security mac-address sticky 這條命令就是將前三個(gè)接入到這個(gè)端口的計(jì)算機(jī)的MAC地址自動(dòng)的加入到我們的MAC地址表中。 |
Switch(config)#interface fastEthernet 0/2 Switch(config-if)#switchport mode access Switch(config-if)#switchport port-security Switch(config-if)#switchport port-security mac-address sticky |
Switch#show mac-address-table Mac Address Table ------------------------------------------- Vlan Mac Address Type Ports ---- ----------- -------- ----- 1 0009.7c11.89e7 DYNAMIC Fa0/3 1 000a.41a9.79b0 DYNAMIC Fa0/2 1 00e0.a342.20e6 STATIC Fa0/1 Switch# |
Switch#show mac-address-table Mac Address Table ------------------------------------------- Vlan Mac Address Type Ports ---- ----------- -------- ----- 1 0009.7c11.89e7 DYNAMIC Fa0/3 1 000a.41a9.79b0 STATIC Fa0/2 1 00e0.a342.20e6 STATIC Fa0/1 Switch# |
Switch#show port-security Secure Port MaxSecureAddr CurrentAddr SecurityViolation Security Action (Count) (Count) (Count) -------------------------------------------------------------------- Fa0/1 1 1 3 Restrict Fa0/2 1 1 0 Shutdown ---------------------------------------------------------------------- Switch# |
聯(lián)系客服