Cisco WS-C2960S-24PD-L Software Guide - Page 209

Disabling Port Security, Configuring Port Security Aging

Page 209 highlights

Chapter 7 Configuring the Switch Ports Enabling Port Security Step 3 Step 4 Step 5 Step 6 Command port security max-mac-count 1 port security action shutdown end show port security Purpose Secure the port and set the address table to one address. Set the port to shutdown when a security violation occurs. Return to privileged EXEC mode. Verify the entry. Disabling Port Security Beginning in privileged EXEC mode, follow these steps to disable port security: Step 1 Step 2 Command configure terminal interface interface Step 3 Step 4 Step 5 no port security end show port security Purpose Enter global configuration mode. Enter interface configuration mode for the port you want to disable port security. Disable port security. Return to privileged EXEC mode. Verify the entry. Configuring Port Security Aging Note This feature is not available on the Catalyst 2900 LRE XL switches. You can use port security aging to set the aging time for all dynamic and static secure addresses on a port. When port security aging is enabled on a port, the secure addresses on the port are deleted only if the secure addresses are inactive for the specified aging time. Use this feature to remove and add PCs on a secure port without manually deleting the existing secure MAC addresses and to still limit the number of secure addresses on a port. Beginning in privileged EXEC mode, follow these steps to enable the port security aging feature: Step 1 Step 2 Command configure terminal interface interface Step 3 port security aging time time Step 4 end Step 5 show port security [interface-id] Purpose Enter global configuration mode. Enter interface configuration mode for the port on which you want to enable port security aging. Enable port security aging for this port and set the aging time. For time, specify the age time for this port. Valid range is from 0 to 1440 minutes. If the time is equal to 0, aging is disabled for this port. Return to privileged EXEC mode. Verify the entry. 78-6511-08 Catalyst 2900 Series XL and Catalyst 3500 Series XL Software Configuration Guide 7-11

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368

7-11
Catalyst 2900 Series XL and Catalyst 3500 Series XL Software Configuration Guide
78-6511-08
Chapter 7
Configuring the Switch Ports
Enabling Port Security
Disabling Port Security
Beginning in privileged EXEC mode, follow these steps to disable port security:
Configuring Port Security Aging
Note
This feature is not available on the Catalyst 2900 LRE XL switches.
You can use
port security aging to set the aging time for all dynamic and static secure addresses on a
port. When port security aging is enabled on a port, the secure addresses on the port are deleted only if
the secure addresses are inactive for the specified aging time.
Use this feature to remove and add PCs on a secure port without manually deleting the existing secure
MAC addresses and to still limit the number of secure addresses on a port.
Beginning in privileged EXEC mode, follow these steps to enable the port security aging feature:
Step 3
port security max-mac-count 1
Secure the port and set the address table to one address.
Step 4
port security action shutdown
Set the port to shutdown when a security violation occurs.
Step 5
end
Return to privileged EXEC mode.
Step 6
show port security
Verify the entry.
Command
Purpose
Command
Purpose
Step 1
configure terminal
Enter global configuration mode.
Step 2
interface
interface
Enter interface configuration mode for the port you want to disable port
security.
Step 3
no port security
Disable port security.
Step 4
end
Return to privileged EXEC mode.
Step 5
show port security
Verify the entry.
Command
Purpose
Step 1
configure terminal
Enter global configuration mode.
Step 2
interface
interface
Enter interface configuration mode for the port on which you want to enable
port security aging.
Step 3
port security
aging
time
time
Enable port security aging for this port and set the aging time. For
time
,
specify the age time for this port. Valid range is from 0 to 1440 minutes. If the
time is equal to 0, aging is disabled for this p
ort.
Step 4
end
Return to privileged EXEC mode.
Step 5
show port security
[
interface-id
]
Verify the entry.