Specifications

4.11.4 CLICommandsoftheSecurity
CommandLinesoftheSecurityconfiguration
Feature CommandLine
PortSecurity
AddMAC Switch(config)#macaddresstablestatic0012.7701.0101vlan1interface
fa1
macaddresstableunicaststaticsetok!
PortSecurity Switch(config)#interfacefa1
Switch(configif)#switchportportsecurity
DisablesnewMACaddresseslearningandagingactivities!
N
ote:Rule:AddthestaticMAC,VLANandPortbindingfirst,thenenable
theportsecuritytostopnewMAClearning.
DisablePortSecurity Switch(configif)#noswitchportport security
EnablenewMACaddresseslearningandagingactivities!
Display Switch#showmacaddresstablestatic
DestinationAddressAddressTypeVlanDestination
Port
‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐ ‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐ ‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐‐
0012.7701.0101Static1fa1
IPSecurity
IPSecurity Switch(config)#ipsecurity
Setipsecurityenableok.
Switch(config)#ipsecurityhost192.168.2.200
A
ddipsecurityhost192.168.2.200 ok.
Display Switch#showipsecurity
ipsecurityisenabled
ipsecurityhost:
192.168.2.200
802.1x
enable
diable
Switch(config)#dot1xsystemauthcontrol
Switch(config)#
Switch(config)#nodot1xsystemauthcontrol
Switch(config)#
authenticmethod Switch(config)#dot1xauthenticmethod
localUsethelocalusernamedatabaseforauthentication
radiusUsetheRemoteAuthenticationDialInUserService
(RADIUS)server sforauthentication
Switch(config)#dot1xauthenticmethodradius
Switch(config)#
radiusserverip Switch(config)#dot1xradius
Switch(config)#dot1xradiusserverip192.168.2.200key1234
RADIUSServerPortnumberNOTgiven.(default=1812)
RADIUSAccountingPortnumberNOTgiven.(def ault=1813)
RADIUSServerIP:192.168.2.200
RADIUSServerKey:1234
RADIUSServerPort:1812
RADIUSAccountingPort:1813
Switch(config)#
radiusserverip Switch(config)#dot1xradius
Switch(config)#dot1xradiusserverip192.168.2.200key1234
119