 




<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Network technologies and trends &#187; Port security</title>
	<atom:link href="http://itknowledgeexchange.techtarget.com/network-technologies/tag/port-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://itknowledgeexchange.techtarget.com/network-technologies</link>
	<description></description>
	<lastBuildDate>Wed, 15 May 2013 18:52:38 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	
		<item>
		<title>Review for &#8220;31 days before your CCNA Exam&#8221;. A title worth reading.</title>
		<link>http://itknowledgeexchange.techtarget.com/network-technologies/review-for-31-days-before-your-ccna-exam-a-tile-worth-reading/</link>
		<comments>http://itknowledgeexchange.techtarget.com/network-technologies/review-for-31-days-before-your-ccna-exam-a-tile-worth-reading/#comments</comments>
		<pubDate>Thu, 07 Oct 2010 22:20:47 +0000</pubDate>
		<dc:creator>Yasir Irfan</dc:creator>
				<category><![CDATA[31 days before your CCNA Exam]]></category>
		<category><![CDATA[Allan Johnson]]></category>
		<category><![CDATA[CCNA skills]]></category>
		<category><![CDATA[CCNA Skills review and practice]]></category>
		<category><![CDATA[Cisco CCNA 640-802 Certification exam]]></category>
		<category><![CDATA[Cisco Network Academy]]></category>
		<category><![CDATA[Cisco Network Academy students]]></category>
		<category><![CDATA[Cisco Packet Tracer]]></category>
		<category><![CDATA[Cisco Press]]></category>
		<category><![CDATA[EIGRP]]></category>
		<category><![CDATA[Exam day and post exam information]]></category>
		<category><![CDATA[frame-relay configuration]]></category>
		<category><![CDATA[GNS3 graphical network simulator]]></category>
		<category><![CDATA[inter vlan routing]]></category>
		<category><![CDATA[Jamie topology]]></category>
		<category><![CDATA[Port security]]></category>
		<category><![CDATA[Review for 31 days before your CCNA Exam]]></category>
		<category><![CDATA[STP]]></category>
		<category><![CDATA[VTP]]></category>
		<category><![CDATA[which covers topics like VLAN configuration]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/network-technologies/review-for-31-days-before-your-ccna-exam-a-tile-worth-reading/</guid>
		<description><![CDATA[In short an interesting title, exclusively written for the Cisco Network Academy students, who are preparing for the Cisco CCNA 640-802 Certification exam. The author Allan Johnson takes a very broad look at practical way to make you understand the concepts in 31 days in a very concise way.  He has emphasized on concepts and [...]]]></description>
				<content:encoded><![CDATA[<p>In short an interesting <a href="//www.ciscopress.com/bookstore/product.asp?isbn=1587131749">title</a>, exclusively written for the Cisco Network Academy students, who are preparing for the Cisco CCNA 640-802 Certification exam. The author Allan Johnson takes a very broad look at practical way to make you understand the concepts in 31 days in a very concise way.  He has emphasized on concepts and terminologies used in Cisco CCNA 640-802 Certification exam in an interesting way which definitely helps you to summarize your learning.</p>
<p><a href="http://cdn.ttgtmedia.com/ITKE/uploads/blogs.dir/58/files/2010/10/31-days1.jpg"><img class="alignnone size-medium wp-image-938" src="http://cdn.ttgtmedia.com/ITKE/uploads/blogs.dir/58/files/2010/10/31-days1.jpg" alt="" width="280" height="420" /></a></p>
<p>Pic Courtesy: Cisco Press</p>
<p>Although the title <a href="//www.ciscopress.com/bookstore/product.asp?isbn=1587131749">&#8220;31 days before your CCNA Exam&#8221;</a> aims at Cisco Network Academy students, but it can be used for the Cisco CCNA 640-802 Certification aspirers who does self study.</p>
<p>The author Allan Johnson divided the title suiting in to 31 chapters, which are so concise you can finish each chapter in an hour. The cream of the title  <a href="//www.ciscopress.com/bookstore/product.asp?isbn=1587131749">&#8220;31 days before your CCNA Exam&#8221;</a> is the section called &#8220;Exam day and post exam information&#8221; which gives the CCNA Certification aspirers guidelines on what to expect after the completion of exam as well as what they should do if they fail to pass the exam on first attempt. One more section that I really liked is &#8220;CCNA Skills review and practice&#8221; which helps you to practice the CCNA skills which includes most of the CCNA 640-802 exam configurations skills in one topology, which covers topics like VLAN configuration, frame-relay configuration, inter vlan routing, EIGRP,VTP, port security , STP. You can practice those topologies either on Cisco Packet Tracer or GNS3 graphical network simulator.</p>
<p>Overall the title <a href="//www.ciscopress.com/bookstore/product.asp?isbn=1587131749">&#8220;31 days before your CCNA Exam&#8221;</a> is a true gem, but cannot be a only source for passing CCNA 640-802 exam, this title is good for the some one who is looking for quick reference on CCNA 640-802 exam topics in an well organized way. I thank <a href="http://www.ciscopress.com">Cisco Press</a> and Jamie in particular for providing me the copy of <a href="http://www.ciscopress.com/bookstore/product.asp?isbn=1587131749">&#8220;31 days before your CCNA Exam&#8221;</a></p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/network-technologies/review-for-31-days-before-your-ccna-exam-a-tile-worth-reading/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Introduction to Cisco port security and the reasons to implement</title>
		<link>http://itknowledgeexchange.techtarget.com/network-technologies/introduction-to-port-security-and-the-reasons-to-implement/</link>
		<comments>http://itknowledgeexchange.techtarget.com/network-technologies/introduction-to-port-security-and-the-reasons-to-implement/#comments</comments>
		<pubDate>Tue, 17 Jun 2008 06:48:52 +0000</pubDate>
		<dc:creator>Yasir Irfan</dc:creator>
				<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Cisco 2950]]></category>
		<category><![CDATA[Cisco 3560]]></category>
		<category><![CDATA[Cisco 3560-E]]></category>
		<category><![CDATA[Cisco 3750-E]]></category>
		<category><![CDATA[Cisco 6500]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Port security]]></category>
		<category><![CDATA[Switches]]></category>

		<guid isPermaLink="false">http://itknowledgeexchange.techtarget.com/network-technologies/introduction-to-port-security-and-the-reasons-to-implement/</guid>
		<description><![CDATA[A growing challenge facing network administrators is determining how to control who can access the organization&#8217;s internal network—and who can&#8217;t. For example, can anyone walk into campus LAN , plug in a laptop, and access the network? You might argue that the wall jack has no connection to a switch, but couldn&#8217;t someone just pull [...]]]></description>
				<content:encoded><![CDATA[<p>A growing challenge facing network administrators is determining how to control who can access the organization&#8217;s internal network—and who can&#8217;t. For example, can anyone walk into campus LAN , plug in a laptop, and access the network? You might argue that the wall jack has no connection to a switch, but couldn&#8217;t someone just pull the Ethernet cable from a working PC and connect to the network that way?</p>
<p>You might think this an unlikely scenario, but it does happen. For example a salesmen coming in to demo products, and they would just pull the Ethernet jack off a PC and connect it to their laptop, hoping to get Internet access.</p>
<p>I turned to switch port security to help solve the problem. Let&#8217;s look at how we can use Cisco&#8217;s Port Security feature to protect our organization.</p>
<p><strong>Understand the basics</strong><br />
In its most basic form, the Port Security feature remembers the Ethernet MAC address connected to the switch port and allows only that MAC address to communicate on that port. If any other MAC address tries to communicate through the port, port security will disable the port. Most of the time, network administrators configure the switch to send a SNMP trap to their network monitoring solution that the port&#8217;s disabled for security reasons. When using port security, we can prevent devices from accessing the network, which increases security.</p>
<p><strong>Benefits to port Securty</strong><br />
The key benefits of Port Security are:<br />
•Network Availability &#8211; Reduce campus wide network outages caused by broadcast storms by blocking non standard hubs and switches.<br />
•Network Reliability &#8211; Network port bandwidth can be guaranteed if limited to one MAC address. Bandwidth can&#8217;t be guaranteed if other network devices are sharing the network port.<br />
•DHCP Availability &#8211; Reduce the risk of over subscription of DHCP IP Address per VLAN by limiting one MAC address per port.<br />
•Network Security &#8211; Limiting one MAC address per switch port is an attack mitigation strategy. Stops CAM tables flooding attacks forcing the switch into repeater mode. Tools like macof can be used for this type of attack.<br />
•Future Proofing – The implementation of port authentication at the edge of the network (802.1x) will also limit user to one MAC address per port.</p>
<p>Applying Cisco Security Features to Solve Common Problems</p>
<p><strong>Sample Configuration for port security</strong><br />
Configuring the Port Security feature is relatively easy. In its simplest form, port security requires going to an already enabled switch port and entering the port-security Interface Mode command. Here&#8217;s an example:</p>
<p>Switch)# config t<br />
Switch(config)# int fa0/18<br />
Switch(config-if)# switchport port-security ?<br />
aging Port-security aging commands<br />
mac-address Secure mac address<br />
maximum Max secure addresses<br />
violation Security violation mode</p>
<p>Switch(config-if)# switchport port-security<br />
Switch(config-if)#^Z</p>
<p>By entering the most basic command to configure port security, we accepted the default settings of only allowing one MAC address, determining that MAC address from the first device that communicates on this switch port, and shutting down that switch port if another MAC address attempts to communicate via the port. But you don&#8217;t have to accept the defaults.</p>
<p><strong>Know your options</strong><br />
As you can see in the example, there are a number of other port security commands that you can configure. Here are some of your options:<br />
switchport port-security maximum {max # of MAC addresses allowed}: You can use this option to allow more than the default number of MAC addresses, which is one. For example, if you had a 12-port hub connected to this switch port, you would want to allow 12 MAC addresses—one for each device. The maximum number of secure MAC addresses per port is 132.<br />
switchport port-security violation {shutdown | restrict | protect}: This command tells the switch what to do when the number of MAC addresses on the port has exceeded the maximum. The default is to shut down the port. However, you can also choose to alert the network administrator (i.e., restrict) or only allow traffic from the secure port and drop packets from other MAC addresses (i.e., protect).<br />
switchport port-security mac-address {MAC address}: You can use this option to manually define the MAC address allowed for this port rather than letting the port dynamically determine the MAC address.</p>
<p>Of course, you can also configure port security on a range of ports. Here&#8217;s an example:<br />
Switch)# config t<br />
Switch(config)# int range fastEthernet 0/1 &#8211; 24<br />
Switch(config-if)# switchport port-security<br />
However, you need to be very careful with this option if you enter this command on an uplink port that goes to more than one device. As soon as the second device sends a packet, the entire port will shut down.</p>
<p><strong>View the status of port security</strong><br />
Once you&#8217;ve configured port security and the Ethernet device on that port has sent traffic, the switch will record the MAC address and secure the port using that address. To find out the status of port security on the switch, you can use the show port-security address and show port-security interface commands. Below are examples for each command&#8217;s output:<br />
Switch# show port-security address<br />
Secure Mac Address Table<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Vlan Mac Address Type Ports Remaining Age<br />
(mins)<br />
&#8212;- &#8212;&#8212;&#8212;&#8211; &#8212;- &#8212;&#8211; &#8212;&#8212;&#8212;&#8212;-<br />
1 0004.00d5.285d SecureDynamic Fa0/18 -<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-<br />
Total Addresses in System (excluding one mac per port) : 0<br />
Max Addresses limit in System (excluding one mac per port) : 1024</p>
<p>Switch# show port-security interface fa0/18<br />
Port Security : Enabled<br />
Port Status : Secure-up<br />
Violation Mode : Shutdown<br />
Aging Time : 0 mins<br />
Aging Type : Absolute<br />
SecureStatic Address Aging : Disabled<br />
Maximum MAC Addresses : 1<br />
Total MAC Addresses : 1<br />
Configured MAC Addresses : 0<br />
Sticky MAC Addresses : 0<br />
Last Source Address : 0004.00d5.285d<br />
Security Violation Count : 0</p>
<p>Switch#</p>
<p>Yasir<br />
Personel website:www.yasirirfan.com</p>
<!-- wpms-network-global-inserts -->]]></content:encoded>
			<wfw:commentRss>http://itknowledgeexchange.techtarget.com/network-technologies/introduction-to-port-security-and-the-reasons-to-implement/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
