Laboratory of port security exercise - do not behave as expected.

Hello

I'm working on a CCENT training lab to demonstrate the configuration of port security.

I have a Catalyst 3550 switch software Cisco's IOS, software of C3550 (C3550-IPSERVICESK9-M), SE Version 12.2 (52), VERSION of the SOFTWARE (fc3). I have two computers connected on ports fa0/1 and fa0/2 with IP addresses of 10.0.0.20/24 and 10.0.0.12/24 respectively. Without active port security, each computer can ping successfully the other.

As soon as I change the configuration to add port security on fa0/1 I am not able to ping between the two computers, nor can I ping 10.0.0.20 from the console of the switch, but I don't know why! If I delete it again the pings succeed again.

I expect that the switch must learn the computer connected to fa0/1 MAC and stop if there is subsequently any traffic from another Mac.

Interestingly, the 'show mac address-table' command shows that the MAC connected to fa0/1 when port security is not enabled. I don't know if this is relevant.

Can someone help me diagnose what is happening?

Thank you.

Configuration before change:

interface FastEthernet0/1

switchport mode access

Speed 100

full duplex

spanning tree portfast

!

interface FastEthernet0/2

switchport mode access

Speed 100

full duplex

spanning tree portfast

!

Configuration after modification:

interface FastEthernet0/1

switchport mode access

switchport port-security

Speed 100

full duplex

spanning tree portfast

!

interface FastEthernet0/2

switchport mode access

Speed 100

full duplex

spanning tree portfast

!

Other diagnoses (after change):

S1 # show ip interface brief

Interface IP-Address OK? Method State Protocol

Vlan1 10.0.0.5 YES NVRAM up up

FastEthernet0/1 no YES unset upward, upward

FastEthernet0/2 not assigned YES unset upward, upward

#show S1 port-security

Secure the security Port MaxSecureAddr CurrentAddr SecurityViolation Action

(County)       (County)          (County)

---------------------------------------------------------------------------

FA0/1 1 0 0 stop

---------------------------------------------------------------------------

Total addresses in the system (with the exception of a mac per port): 0

Limit Max addresses in the system (with the exception of a mac per port): 5120

S1 #show - interface fa0/1 port security

Port security: enabled

Port State: Secure-up

Mode of violation: stop

Aging time: 0 mins

Type of aging: absolute

Aging of SecureStatic address: disabled

Maximum MAC addresses: 1

MAC addresses total: 0

Configured MAC addresses: 0

Sticky MAC addresses: 0

Last Source address: Vlan: 0000.0000.0000:0

Security Violation count: 0

S1 #show interfaces fa0/1

FastEthernet0/1 is up, line protocol is up (connected)

Material is Fast Ethernet, the address is 000f.f796.d781 (bia 000f.f796.d781)

MTU 1500 bytes, BW 100000 Kbit, DLY 100 usec,

reliability 255/255, txload 1/255, rxload 1/255

Encapsulation ARPA, loopback not set

KeepAlive set (10 sec)

Full-duplex, 100 MB/s, media type is 10/100BaseTX

input stream control is turned off, output flow control is not supported

Type of the ARP: ARPA, ARP Timeout 04:00

Last entry exit ever, 00:00:01, blocking exit ever

Final cleaning of "show interface" counters never

Input queue: 0/75/0/0 (size/max/drops/dumps); Total output drops: 0

Strategy of queues: fifo

Output queue: 0/0 (size/max)

5 minute input rate 0 bps, 0 packets/s

5 minute output rate 0 bps, 0 packets/s

3494 packets input, 587250 bytes, 0 no buffer

Received 1593 broadcasts (0 multicasts)

0 Runts, 0 giants, 0 shifters

entry 0, 0 CRC errors, frame 0, saturation 0, 0 ignored

0 watchdog, 1254 multicast, break 0 comments

entry packets 0 with condition of dribble detected

39631 packets output, 3311977 bytes, 0 underruns

0 output errors, 0 collisions, 1 interface resets

0 babbles, collision end 0, 0 deferred

carrier, 0 no carrier, lost 0 0 output BREAK

output buffer, the output buffers 0 permuted 0 failures

#show mac address table S1 | include DYN

1 b827.ebed.e2d9 DYNAMICS Fa0/2

S1 #show ip arp

Protocol of age (min) address Addr Type Interface equipment

Internet 10.0.0.12 5 b827.ebed.e2d9 ARPA Vlan1

Internet 10.0.0.5 - 000f.f796.d780 ARPA Vlan1

Internet 10.0.0.20 32 10dd.b1f1.0c64 ARPA Vlan1

Do you have any other platform to configure your lab? because it should work ideally and the configuration is fine. However, to complete your lab, you already have workaround...

I suspect that this question is something related to the hardware you use or due to a BUG.

Please note the useful comment

Tags: Cisco Network

Similar Questions

  • Return newline and carriage return not behave as expected.

    In my PDF file I have a multiline form called OutputText and when I put its value it does not display properly. In the debugger I type is:

    this.getField("OutputText").value = "hello\nthere!"

    or

    this.getField("OutputText").value = "hello\rthere!"

    Then, after Ctrl + Enter, the debugger displays

    Hello

    here!

    but the OutputText shows:

    Hello

    here!

    The exhaust of the \n and \r characters do not behave properly, they seem to be removing the character following that escaped.

    Anyone has any idea why?

    I started again with a new PDF and new form, with no other writing and got the same results.

    I used under Tools\Content, select an object to change the properties of the text field.

    When I activated the option for "allow Rich Text Formatting' the first following letter each instance of '\n' and '\r' appeared and disappears from the text box.

    I don't know yet how the \n and \r are supposed to behave, but at least there is a reason.

  • Venue 11 Pro - Slim keyboard do not behave as expected, or it must.

    I recently received a dell flat keyboard for my 11 Pro - Baytrail tablet coming.    Overall, I like the quality and functionality, although I also like others encountered the intermittent non-functional keyboard, but this isn't the subject of this post.

    I noticed a few things in his behavior that do not work as you might expect, and I hope that can be corrected through the software.

    1. when the keyboard is connected but folded behind the Tablet back (that is to say the keyboard is not in use) keyboard on screen does not appear.  Which makes it difficult to use the device as a tablet like whenever the data entry is required you must unfold the keyboard and hold it down somehow while you type, then fold back behind the screen to continue the use of the tablet.   When folding keyboard behind the unit of its equally important to set the keyboard to display on layout as it should stop the keyboard itself to operate, right now the keyboard no longer works as it should be unless an alternative entry is available.

    2. in the same way as #1.  When the keyboard is attached, but folded back behind the orientation of the Tablet is locked if the screen does not turn in portrait or landscape mode if necessary.  So, if you carried it with the lid / slim keyboard on and open it upwards, folding of behind the screen, the keyboard is locked in landscape mode.   The only method I've found to change his orientation is to go to the desktop and run the application of graphics intel to change direction.

    Combined makes the slim keyboard worse than useless in several scenarios of use.   I want the keyboard slim for the occasional need to enter more data as possible on the touchscreen AND protect the tablet... but if your use is more compressed than laptop, you'll find yourself constantly work around these limitations.

    You have a great product here, but you really need to take a page from the playbook of the surface here.   They sort of set the standard and expectations for how keyboard covers on tablets should work, and although I really like the material usage is clumsy, in its current form.

    Glad to hear you guys are to find some kind of workaround for this.  About the requested changes, I've confirmed with engineering teams that unfortunately these elements are not possible given the current design of equipment.   They are documented for future products however.   Appreciate all the comments on this issue and my apologies for not being able to provide a solution for this product.

  • Display.screenshot does not behave as expected

    Hello

    The Display.screenshot method doesn't seem to work as expected. When I call this method, I got the dialog box asking the user or not to allow a screen capture to take. If the user selects Hello but leaves theDo ask not agai box unchecked, the screenshot is not taken. If, however, select 'allow' and check the box "Do not ask again" the screenshot is taken. Maybe that's a problem with the dialog box?

    Here is my code below-
    try {}
    Display.screenshot (this.bitmap, 0,0, Display.getWidth (), Display.getHeight ());
    }
    /**
    * If the user does not have a screen capture taken just display the General image
    */
    {} catch (ControlledAccessException cae)
    This.Bitmap = Constants.BACKGROUND_IMAGE;
    }

    Depends on how you code.

    Personally I d code it as follows:

    (a) have an indicator of persistent screenshot with three States

    0 - does not define

    -1 can't screenshot

    1 is allowed to the screenshot.

    Check this box if you are about to make a screenshot.  In this case - 1 indicate to the user that they have disabled this function be selected permissions.  If it's 0 or + 1, check the permissions API to see if you are allowed to do.  If you are, then set the value to 1 and do.  If you're not, tell them that they need to enable and display the permissions API.  When that is saved, check again.  If they helped him, set the indicator 1 and continue.  If they don't have not enabled it, it the value - 1 and tell them that you can't capture screens because they were disabled.

    Not sure which covers all cases, but you get the idea.

    Ok?

  • RegEx does not behave as expected

    Hello, all,.

    I think I may have posted about this, before, but received no response; I have to (unfortunately), then try again.

    I use a regular Expression to map the complete physical location on the hard disk where the site is located.  I need this for a CFFILE tag.

    I use a regular expression instead of hard coding the location is because the location varies depending on whether it is used in the production, development or put in scene.  (Yes, I know, all three should be mirrors of each other - I'm working on it.)  )

    For example, our DEV environment should the CFFILE tag to point to the E:\ColdFusion10\cfusion\wwwroot\www\ folder.

    Our environment needs the CFFILE tag to point to the C:\ColdFusion10\cfusion\www\ folder.

    Our production environment should the CFFILE to point to the F:\webdocs\cf\www\docs\ folder.

    I don't want to really be hackers on this matter and use CFIF or CFSWITCH to set the variable 'this.webrootmapping '.  In addition, if nothing is changed, I have to come in and change the code.  Is not ideal.

    So, I use a regular expression.  I'll also put it so that it will always point to the ROOT, no matter what subfolder, the user is in.

    What I (and does not work for the production environment) is:

    <cfset this.webrootmapping = REreplaceNoCase(ExpandPath('./'),
               '(.+[\\|\/]www([\\|\/]docs)?[\\|\/])(.+)',
               '\1',
               'all') />
    

    EC that it is supposed to do, is accept all the folder "www" or "www\docs" folder and delete all after that.

    It's in dev and staging; It does NOT work in production (where the root ends in "\docs\".)  The question mark must be indicating "zero or one \docs".  But it's not.

    Any idea is appreciated.

    V/r,

    ^_^

    * headdesk *.
    * headdesk *.
    * headdesk *.
    * headdesk *.
    * headdesk *.

    * HEADDESK *.

    He begins to slowly kill me the way I type everything and then it solves itself somehow.

    * headdesk *.
    * headdesk *.
    * headdesk *.

    I experience something of VERY, VERY simple, and it is now resolved.

    * headdesk *.
    * headdesk *.
    * headdesk *.

    I'll share it with you, after I'm done banging my head into my office.

    * headdesk *.
    * headdesk *.
    * headdesk *.
    * headdesk *.
    * headdesk *.
    * headdesk *.
    * headdesk *.
    * headdesk *.
    * headdesk *.
    * headdesk *.

    The last '+' (one or more) has been replaced by ' *' (zero or more) and it worked.  Just in case someone else is going through this problem and spend weeks or months trying to understand.

    * headdesk *.
    * headdesk *.
    * headdesk *.

    I need a NAP, now.

    * headdesk *.
    * headdesk *.
    * headdesk *.

    Good night.

    V/r,

    ^_^

    * headdesk *.
    * headdesk *.
    * headdesk *.

  • Boxes do not behave as expected

    All,

    I'm pulling my hair out here.  I have a movieclip that contains check boxes "preferences_mc."  I have an xml file that is loaded and has a component called 'isUnique' who has children with unique id, title, version and other names.  What I'm trying to accomplish is the form that I'm building to be able to select/deselect each box and save the output to an xml file selection.  I got that far, and everything works perfectly.  My problem is that once I loaded the XML back in and try to settle the checkbox.selected = xmlPrefs.isUnique.id to get the checkbox use data from the xml file to determine whether it is selected or unselected, he ALWAYS chooses the area either true or false.  I've tried everything.  xmlPrefs.isUnique.id trace as false which is correct but the screen still shows the selected checkbox.  I even tried casting the xml as a type Boolean and returns always as a selected checkbox.  I can select/deselect each box and save the preferences of output to a file xml correctly as well as read only in properly, it just will NOT set the selection of boxes correctly.  Someone has an idea, because apparently, I'm lost.  Oh, by the way, I also tried to create a new instance in actionscript and attempted to set the property .selected and then addChild and he STILL selected even though it traces the value false.

    Hello

    Try this:

    var isUnique:Boolean = (xmlPrefs.isUnique.id == 'true')? true: false;

    CheckBox.Selected = isUnique;

    In fact, when extracting the values to an xml file, they come as string and where just type them cast returns true only as it just check for a value to be present.

    Best regards

    Etienne Das

    http://deepanjandas.WordPress.com/

  • Scattergraph MoveCursor method does not behave as expected

    I'm trying to do something very simple: essentially keep the cursor on the last point being traced all trying to trace several scatterplots. Here is a snippet of code where I put the cursor properties:

    ********************************************************************************************************************************************************************************

    internal NationalInstruments.UI.WindowsForms.ScatterGraph sgImpedance;

    private list m_ZDataPlots = new list (); //clsZofFDataType is a class that represents the data in a conspiracy.

    ... / / more code follows here

    ...

    sgImpedance.Cursors [0]. Plot = sgImpedance.Plots [m_ZDataPlots.Count - 1]; sgImpedance is a scattergraph initialized as above
    sgImpedance.Cursors [0]. Color = newColor;
    sgImpedance.Cursors [0]. SnapMode = CursorSnapMode.NearestPoint;

    If (sgImpedance.Plots [m_ZDataPlots.Count - 1].) HistoryCount > 1)
    sgImpedance.Cursors [0]. MoveCursor (sgImpedance.Plots [m_ZDataPlots.Count - 1].) HistoryCount - 1);
    on the other
    sgImpedance.Cursors [0]. MoveCursor (0);

    ********************************************************************************************************************************************************************************

    The cursor keeps however remain at the centre of the plot; It is on the correct path but it is never the last traces. Is there any attribute I need to, or an event that should be raised so that the cursor to stay on the current point being traced? I have attached a screenshot to show what is happening.

    Any help will be appreciated. If I need to elaborate further, please let me know. Thank you very much!

    Can you provide an example of a code so I can reproduce the behavior on my end?

  • N2048 port security does not

    Hi Experts,

    Only, we have deployed a new site that uses the Dell N2048 switches in a stack.

    Now we would add port security to the switch, Port-MAC locking to lockdown one port if another computer.

    According to the manual, to put in place we only need of to the port to locked under the MISTLETOE under switching, network security, port security.

    This does not activate it.

    We tried to add via the command line, in the ports of test, it now shows:

    switchport security of dynamic ports 1

    Still, port security is not enabled. There is another thing that must be enabled in the world to do this job or other commands?

    Thank you

    The output of port security-# show is as follows:

    Port Security Administration Mode: enabled

    It is possible that the tests were not done fast enough. I spent the time-out and ask them to test again.

    Thank you

  • What should be the port/security settings for Windows Mail with Vista - I think they changed?

    I had to reinstall Vista when my hard drive crashed, and Windows Mail does not work completely correctly. I think remember me an email from Microsoft told me to change the ports/security settings. Could someone tell me what they should be?

    A "error message indicating", what exactly? No error code or the relevant text?
     
    Make sure these settings match exactly.
     
     

    Leave messages on the server and it clutter?
     
     
  • Security updates have blocked incoming messages in Windows Mail - security popup does not accept the password, error number: 0x800CCC92

    Original title: updates blocked mail in Windows Mail - security popup does not accept the password

    Hello - three updates installed security today (KB2691442, 2718523, 2596744).

    Now Windows mail will no longer accept mail entering into my pop3 account.  Security pop - up demand for a/c of the user and the password - I've checked tools > accounts > properties, reset the password, but it does not accept pop-up.  Here is the error message:

    .... POP3, server response: '-ERR [AUTH] username and password not accepted.', Port: 995, secure (SSL): Yes, Server error: 0x800CCC90, error number: 0x800CCC92

    Help please! John

    Hello

     
    See the steps in the links.
    Troubleshoot Windows Mail

    Windows Mail: Setting up an account of end-to-end

    Hope the information is useful.

  • Need help to reset/compensation port security on a PowerConnect 35XX

    I implement port security on our network, and I've never worked with these before switches. I'm used to the Cisco CLI, who was the command exec "int sticky clear dry port", but it doesn't seem to be anything of the sort on the CLI of Dell.

    Here is the config, I have in place on the switchport in question.

    dot1x multiple-host

    safe standing of port security mode

    port security throw

    For the moment, that the port has done what is supposed to to, but remove the configuration of the interface completely that I am unable to find how the CLI reference or online at how 'quickly' to reset the port.

    Any help would be appreciated.

    Do not take into account. I found buried in the CLI reference command.

    There are actually two commands necessary to reactivate the interface

    "dot1x to re-authenticate ethernet [port]".

    'set interface active ethernet [port] ".

    Thank you

  • Errors of run Switchport Port-Security

    So I'm a bit new to switchport security.  I work on most of the ports in one location.  Its ports where I either switchport voice and switchport access VLAN or just switchport voice VLAN.  For some reason, these types of ports going into err - disable.  Here are a few examples.  Indications as to why it would stop even when I have the right MAC address would be very useful. Interface Fa0/3 has a phone attached to it and a connected computer the phone is off.

    interface FastEthernet0/2
    Description Table phone
    switchport mode access
    switchport voice vlan 2
    switchport port-security
    security violation restrict port switchport
    switchport port-security-address mac 34a8.4ea6.0f95
    spanning tree portfast

    interface FastEthernet0/3
    SAM PHONE x 1623 description
    switchport access vlan 3
    switchport mode access
    switchport voice vlan 2
    switchport port-security maximum 2
    switchport port-security-address mac 442b.031a.2975 - phone MAC
    switchport port-security-address mac e840.f223.8842 - MAC computer
    spanning tree portfast

    2 442b.031a.2975 DYNAMICS Fa0/3

    2 34a8.4ea6.0f95 DYNAMICS Fa0/2

    The newspaper says this whenever I turn on port security.  Any other port where there is only 1 VLAN or 1 device, it works fine no problem.

    27 June 2015 23:59:56: % PORT_SECURITY-2-PSECURE_VIOLATION: security breach took place, caused by MAC address 34a8.4ea6.0f95 on port FastEthernet0/2.
    June 28, 2015 00:00:01: PM-4-ERR_DISABLE %: psecure-violation error found on Fa0/3, putting the Fa0/3 in State of err - disable
    June 28, 2015 00:00:02: % LINEPROTO-5-UPDOWN: Line protocol on Interface FastEthernet0/3, changed state down
    June 28, 2015 00:00:03: % LINK-3-UPDOWN: Interface FastEthernet0/3, changed State to down
    June 28, 2015 00:00:04: PORT_SECURITY-2-PSECURE_VIOLATION %: security breach took place, caused by MAC address 34a8.4ea6.0f95 on port FastEthernet0/2.

    I know I'm missing something because I am new to using switchport security.  I am wanting to lock the ports to prevent devices not allowed to plug in on my network.  I have disabled all DHCP, but I want to take a little further and prevent them to enter the network even and probe the network.

    EDIT - You forgot to mention that it is a 2960 version 15.0 (2) SE5

    Thank you

    David

    David, Kevin,

    Let me join you.

    The way I see the Fa0/2 work with its original configuration is:

    • The maximum number of secure MAC addresses is 1.
    • Access to the VIRTUAL LAN is 1, the voice VLAN is 2.
    • The static safe MAC address 34a8.4ea6.0f95 is added to the access VLAN, not to the voice VLAN
    • When the phone starts to make known by the voice VLAN, MAC address cannot be dynamically added to the list because the maximum allowed number of MAC secure is 1 and the list is already full. The fact that its MAC address is configured statically is irrelevant, because it is not associated with the voice VLAN.

    Try to delete the line

    switchport port-security-address mac 34a8.4ea6.0f95

    and replace with

    voice of vlan switchport port-security-address mac 34a8.4ea6.0f95

    and see if it solves the problem.

    Best regards
    Peter

  • Port security and DHCP

    Hi all.

    I have configured the port security in some ports, and I don't think it handles images as it should. the following settings are

    -max: adds the correct number of MAC

    -permanent safe mode

    -throw

    I connect the legitimate devices to determine the maximum number of MACs, the port must learn and then I connect a device with Mac unsafe. I can get an IP address from the DHCP server, but no traffic is being so forward. I think that no legitimate unit should not be able to get an IP address as port security ignores all frames with an unknown source Mac

    Hi Stelios,

    Your configuration seems to be fine. Mine was connected only with the safety of ports and addresses max I put at 1. I see only 1 MAC address sends bootp all other devices connect via the switch on this port send no bootp.

    You could also make the capture of packets using the capabilities mirror port switch and application of wireshark. Devices are perhaps using old known IP addresses...

    Kind regards

    Aleksandra

  • With the help of port security with Failover PIX

    Hello

    I want to configure port security on a switch in which a pair of PIX failover are configured. However, after

    http://www.Cisco.com/univercd/CC/TD/doc/product/LAN/cat6000/12_1e/swconfig/port_sec.htm

    It seems that this is not possible due to the PIX swapping MAC addresses: "If a workstation with a secure MAC which is configured or learned about a secure port address tries to access another secure port, a violation is marked."

    Does anyone know of a way around this?

    Many thanks in advance,

    Matt

    Hello Matt,

    Unfortunately it not there no work around to your problem.

    Thank you

    Renault

  • All of a sudden I can't open attachments to emails. I get a message that the 'security settings' do not allow. Where are these settings and who put?

    I use TWC (Time Warner Cable) as my server e-mail and Firefox as my browser. I went to my emails and has attempted to open an attachment and got an error message stating "security settings prevent the download file. Well, I contacted TWC, Norton and my PC settings. It seems that Firefox is the problem! If I use another browser ie: Google and go to my email account, I have no problem. I remember recently that Firefox did a download of updates and this may be the cause of the problem.

    Thank you for your private message with the error text: "your current security settings do not allow this file to download."

    Firefox partially integrates with Internet Explorer security settings for download purposes. You can realize your Internet Explorer settings to the 'Internet' zone by following the steps described in this answer to Microsoft forums:

    http://answers.Microsoft.com/en-us/IE/Forum/IE8-windows_other/error-message-your-current-security-settings-do/59cc236d-7baf-4552-92ff-b34b9a6942aa

    Note: Traditionally, the Internet Options dialogue box was available in the Control Panel, as well as in IE. Not sure about Windows 8.1.

    What is fix?

Maybe you are looking for

  • How to add addresses to my address book?

    I want to add in my address book email addresses, but I don't know how to do this. How can I do this?

  • reset the wifi password?

    Hippopotamus: HD Officejet 7110, wifi, passwordMy office has recently reset their password wifi and now my wireless printer not / cannot print.I guess that these two facts are related, but I don't know how to reset thepassword on the printer (if it's

  • boring kb2633880 change

    Addition of the Kb26338802 is repeated rising, the silly, the instaled of forma manual, el pase difficulty it y no encuentro respond. The exclude from futuras plots para what no pero molests aren't the respond. Desde is Muchas Gracias

  • Cannot download pictures from my camera or my backup quickbooks.

    I have recently switched to Verizon internet provider.   All my usb drivers have been updated, but since the passage of the AT & T to Verizon and reconnect my system I have not been able to download pictures from my camera or my Quickbooks backup.  W

  • Help! Premiere and After Effects do more start. (0xc000142)

    Hi allI've tried everything.I reinstalled the whole cloud, even Windows completely, they will still not open.I don't know what to do... I hope you can help me.My system: Windows 10, SSD, 8 GB RAM, AMD Phenom X 6, NVIDIA GTX560Ti.