首页
外语
计算机
考研
公务员
职业资格
财经
工程
司法
医学
专升本
自考
实用职业技能
登录
计算机
The network security policy for Ezonexam requires that only one host be permitted to attach dynamically to each switch interface
The network security policy for Ezonexam requires that only one host be permitted to attach dynamically to each switch interface
admin
2009-05-19
17
问题
The network security policy for Ezonexam requires that only one host be permitted to attach dynamically to each switch interface. If that policy is violated, the interface should be automatically disabled. Which two commands must the Ezonexam network administrator configure on the 2950 Catalyst switch to meet this policy? (Choose two)
选项
A、SWEzonexam1(config-if)# switchport port-security maximum 1
B、SWEzonexam1(config)# mac-address-table secure
C、SWEzonexam1(config)# access-list 10 permit ip host
D、SWEzonexam1(config-if)# switchport port-security violation shutdown
E、SWEzonexam1(config-if)# ip access-group 10
答案
A,D
解析
Explanation
Catalyst switches offer the port security feature to control port access based on MAC addresses. To configure port security on an access layer switch port, begin by enabling it with the following interface configuration command:
Switch(config-if)# switchport port-security
Next, you must identify a set of allowed MAC addresses so that the port can grant them access. You can explicitly configure addresses or they can be dynamically learned from port traffic. On each interface that uses port security, specify the maximum number of MAC addresses that will be allowed access using the following interface configuration command:
Switch(config-if)# switchport port-security maximum max-addr
Finally, you must define how each interface using port security should react if a MAC address is in violation by using the following interface configuration command:
Switch(config-if)# switchport port-security violation {shutdown | restrict | protect}
A violation occurs if more than the maximum number of MAC addresses are learned, or if an unknown (not statically defined) MAC address attempts to transmit on the port. The switch port takes one of the following configured actions when a violation is detected:
shutdown-The port is immediately put into the errdisable state, which effectively shuts it down. It must be re-enabled manually or through errdisable recovery to be used again.
restrict-The port is allowed to stay up, but all packets from violating MAC addresses are dropped. The switch keeps a running count of the number of violating packets and can send an SNMP trap and a syslog message as an alert of the violation.
protect-The port is allowed to stay up, as in the restrict mode. Although packets from violating addresses are dropped, no record of the violation is kept.
转载请注明原文地址:https://kaotiyun.com/show/L0hZ777K
本试题收录于:
思科640802题库思科认证分类
0
思科640802
思科认证
相关试题推荐
The"HardOutHere"videohasrackedup(获胜)over27millionsviewstodateonYouTube.Butthemarketforapopstarmakingcleve
Thesharingeconomyisalittlelikeonlineshopping,whichstartedinAmerica15yearsago.Atfirst,peoplewereworriedabout
Writeanessayof160-200wordsbasedonthefollowingpictures.Inyouressay,youshould1)describethepicturesbriefly,
Supposeyouarethepersonnelmanagerofacompanyandyou’vedecidedtheapplicantnamedZhangWeiisthebestcandidateforth
Apairofdice,rolledagainandagain,willeventuallyproducetwosixes.Similarly,thevirusthatcausesinfluenzaisconstan
In2016,manyshoppersoptedtoavoidthefreneticcrowdsanddotheirholidayshoppingfromthecomfortoftheircomputer.But
Whethertheeyesare"thewindowsofthesoul"isdebatable;thattheyareintenselyimportantininterpersonalcommunicationis
Couldahugadaykeepthedoctoraway?Theanswermaybearesounding"yes!"【B1】______helpingyoufeelcloseand【B2】______to
HowcanBritishtrainoperatorspossiblyjustifyyetanotherincreasetorailpassengerfares?Ithasbecomeagrimlyreliablea
Itwassupposedtobethenew-mediaelection.E-mail,blogging,socialnetworkingandtweetingwereexpectedtosurgeinimporta
随机试题
Actually,IhadreadonebookinEnglish,whenIwasinmiddleschool.Butitwasforgettable.Thistimearound,Iwasinamore
有关PTG干式激光打印机的叙述,错误的是
女性,48岁。间断上腹不适3年,胃镜检查提示重度萎缩性胃炎伴肠化,W-S染色阳性。该患者治疗药物可以选择
血药浓度-过程方程式:c=coe-kt,应同时满足的条件是
房地产经纪行业的公平性管理不包括()。
依据不同的标准,工程索赔可按()进行分类。
【2014.辽宁鞍山】学校课外活动的组织形式不包括()。
在考生文件夹中有工程文件sj5.vbp及其窗体文件sj5.frm,该程序是不完整的,请在有“?”的地方填入正确内容,然后删除“?”及所有注释符(即“’”号),但不能修改其他部分。存盘时不得改变文件名和文件夹。本题描述如下:在名称为Forml的窗
Americansocietyisnotnap-friendly(喜欢午睡)."Infact",saysDavidDinges,asleepspecialistinU.S.A."There’sevenaprohibit
Writingisnotexactlyateamsport.【C1】______awriteryouspendmostofyourtimechuggingawaybyyourlonesome,withonlyy
最新回复
(
0
)