Welcome to Firewall.cx   Cisco Technical Knowledgebase
Modules
· Home
· Alternative Menu
· Amazon
· Cisco Decrypter
· Cisco Lab Partners
· Feedback
· Forums
· Max Arcade
· Private Messages
· Recommend Us
· Statistics
· Stories Archive
· Submit News
· Surveys
· Topics
· Web Links
· Your Account
 
Cisco Knowledgebase Articles
 
Site Info
Your IP: 38.107.191.113

Welcome, Anonymous
Nickname
Password

· Register
· Lost Password
Server Date/Time
31 July 2010 13:40:17 EEST (GMT +3)
 
Top Downloads
 
Gold Lab Partners


 
Firewall.cx: Forums

Firewall.cx :: View topic - Port Security
Forums Home
Forum FAQ :: Search :: Memberlist :: Usergroups
Profile :: Log in to check your private messages :: Log in

View next topic
View previous topic
Post new topic   Reply to topic
Author Message
steveb12
New Member
New Member


Joined: Sep 30, 2003
Posts: 17
Location: Colorado, USA

PostPosted: Thu Mar 04, 2004 12:49 am    Post subject: Port Security Reply with quote

Hey guys. Learnig port security right now and don't understand a Cisco lab I'm currently working on. It is a port security lab involving 3 pc's. 2 are plugged into a 2950 switch, 1 is not plugged into the switch until later.

The lab calls for you to set one of the pc's MAC addy as static on the port it is plugged into. Then, a few steps later the lab tells you to enter in the following commends on the same interface:

switch(config-if)#switchport mode access
switch(config-if)#switchport port-security mac-address sticky

This is the part I do not understand. I thought the previous command instructed the switch to dynamically learn and store the MAC. Though as I stated, a few stpes before this interface was already configured with the MAC as static.

I would greatly appreciate it if someone could explain the point to this. If more information is needed let me know and thanks.
Back to top
View user's profile Send private message
sahirh
Associate Editor & Security Advisor


Joined: Aug 14, 2003
Posts: 1699
Location: Mumbai, India.

PostPosted: Thu Mar 04, 2004 8:42 am    Post subject: Reply with quote

Hey steve, I figure that before this you'd run the command

switchport port-security mac-address <mac-address>

to add a static address to the list right ? Well basically it allows you to have a number of static addresses for one port.. by default the number of secure addresses it lets you add are 1.

However, if you configure fewer secure MAC addresses than the maximum, the remaining MAC addresses are dynamically learned.

Then when you invoke

switchport port-security mac-address sticky

The secure addresses that were dynamically learned are converted to sticky secure MAC addresses and are added to the running configuration. The normal dynamically learned addresses are only added to the address table and thus are lost when the switch restarts.. 'sticky' makes the switch add the newly learned addresses to the running-config as well so they are permanent.

If you want a step-by-step explanation from the horses mouth :
http://www.cisco.com/univercd/cc/td/doc/product/lan/cat2950/12112cea/2955scg/swtrafc.htm#1038501
_________________
Sahir Hidayatullah.
Firewall.cx Staff - Associate Editor & Security Advisor
http://tftfotw.blogspot.com
Back to top
View user's profile Send private message Visit poster's website
Display posts from previous:       
Post new topic   Reply to topic

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum




smartDark Style © 2002 Smartor
Powered by phpBB © 2001, 2002 phpBB Group
 
Forums ©

© Copyright 2000-2010 Firewall.cx - All Rights Reserved

Copyright of all documents and images belonging to this site by Firewall.cx. Information contained on this site is copyrighted material.

It is illegal to copy or redistribute this information in any way without the written consent of Firewall.cx


Firewall.cx disclaims any responsibility for software and information obtained through this site or its links.


Page Generation: 0.66 Seconds