Switchport Security

Cisco CCNP Switch (300-115): The Complete Course Introduction to securing a Switch
6 minutes
All right, welcome back. And here we go switch port security. Again, nothing new. You know that in the switches, Cisco switches, the Canon switches, you can go in there. First of all, you have to do it on the porch, you have to go inside the porch whether it be arrange apart or a single port, you need to go ahead and enable switch port, a port hyphen security. But before you can enable that you got to make sure that the ports are not a dynamic auto, but as an X, these are access ports.

That's number one. Okay, there's a little gotcha there. But those of you who are taking my previous courses should know this. All right. Then you can do a switch port security. All right.

And you can do Mac, sticky, MAC address sticky which means Hey on this dynamically, or you can do an actual MAC address and put it in one by one by one by one. I don't think anybody wants to do that. Okay. So, you're gonna do, it's gonna be based on MAC addresses, okay, you can do it manually, which I don't suggest you do, unless you work for a company with only five people. All right, and then, or I guess that's right here, use a sticky command, which which they've used a sticky command, what's going to happen? What that means is, when it alarms, it's going to learn it automatically.

But when you look at the MAC address table, it's going to say, static to statically. There. Alright, so that's the difference. What's the good use thinking? Okay, don't do it manually. That's insane.

Again, unless you work for a company by people, and you should also choose, you know, the violation, how many MAC addresses you're going to use and so forth. Okay. So let's take a look at the configuration. See, I post those poor mode out First, make sure now if you've done VLANs, or within your switch, and then you do the security, while you're already this switch port mode access, right, because you have to assign the VLANs. And to assign the VLANs they have to be access ports. But either way, if you do it again, it doesn't hurt switch for more access, then go switch port port hyphen security that enables for security, and they do switch port port security, Mac, sticky, Mac sticky, okay, and that says where they are, it's automatically going to learn it.

It's going to learn that but it's gonna look like it's a statically assigned MAC address. Then you decide, okay, well, what is the maximum number? Now I'm going to allow to be learned on this particular port. You can be nice and you can put two or you can be a rule or ruthless dictator. They say only one. Okay, that's it.

Because what's going to happen are when you put the rule and they violate that that particular rule You'll have a maximum of two or maximum one, whatever it is, you're going to put on an action a violation. All right? That should be shut down. All right, and we're going to look at there's different violent violations you can use. All right, but I like putting shut down or shut down. Those are put supporting, er are disabled disable or disable, which you manually have to turn that port back on.

I want to take a look at that. Here the violation isn't what I want. Shut down. A means report immediately, or disable. All right, you're gonna, you know, it's gonna beep you know, do anything. You're gonna get a lot of help those calls, hey, I can't get on to this week.

You're gonna get a call more likely. All right, and it's telling you unless you have a third party application that's watching that that's monitoring that. Okay, isn't there Hey, you have a port that's down and warns you about it. They say who was a hoarder? And then you find out and all that good stuff, okay, or you're gonna get it all helped us cause risk straight. This is pretty cool, the port is allowed to stay off the port is off.

But all packets from the violation MAC address are dropped. And it keeps count of those MAC addresses that violated it and assigned to an SNMP trap or a syslog message and alert violation. So either using a trap or SNMP, you can go ahead and keep count of that. All right, which is good. So you don't really need to go and turn on the port. You're going to get alerts that say, hey, these guys are trying to get in.

They're not supposed to this already reached the maximum number of MAC addresses are on there. These MAC addresses don't need to be there. Take a look at what's happening. So I okay gives you a message not bad. Pretty cool. This one though, is pretty much the same as restrict, but it doesn't keep count.

It doesn't keep a record of it. So what the heck. So the port is the law and then You're not keeping track of what's going on. He doesn't keep a track of the violations of it. No. So me louder.

Oh, J DS. I am a ruthless dictator. Okay, I will shut down the port. I don't care. That's my job in it. I will turn it back on.

I will have a third party application that's going to syslog SNMP all this stuff, okay to monitor my network and the load is going to fly up a little fly and tell me Hey, support down. I'm sure I'm going to get calls at the help desk. And then something Hey, man, something's going on with the switch. Okay, so I'm gonna take a look at and say Oh Ha, and I'm going to find out what's going on. So know this table. All right, for poor security.

What it does, this is ridiculous. Protect is protecting what Okay, the first level up, it'll not allow those MAC addresses where you don't know who they are. That doesn't make any sense. Okay, restrict Okay, cool, but no stable and obviously know these commands. All right, for switch port security, that's all it is. That's all it is very simple to do.

And as you're doing your VLANs, when you do a VLAN, VLAN 10, name it, you're already in there, you're in the range report, might as well switch port port security because you did the switch port mode access already. And then just do your search for security while you're there if that is what you're going to do. Alright, well, that's that to the next

