Chapter Intro
Chapter 6 of the CCNA 200-301 Official Cert Guide, Volume 2 discusses Cisco switch port security, from concepts, configuration, to verification. Once enabled on an interface, port security adds logic for each incoming frame, comparing the source MAC address of the frame versus a table and a few other logic steps. The result can be to allow the frame to continue as normal, but the other results can be a variety of steps to prevent the traffic, from simply discarding that frame to both discarding the frame and disabling the interface.
Port security allows us to configure several settings to match incoming frames, including:
- A list of allowed source MAC addresses – both statically defined and dynamically learned
- A number of different source MAC addresses
- An option to store dynamically-learned MAC addresses in the configuration
- Options for three sets of actions to take, called modes: shutdown, violate, and restrict
Packet Tracer has solid support for the port security feature, so join in, configure the features, and experiment with the verification commands.
What are the passwords to enable mode passwords on the devices in your packet tracer labs?
Here is the link to the overview of the Labs
https://blog.certskills.com/packet-tracer-labs/
All passwords are “cisco”