1/29
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced |
|---|
No study sessions yet.
What ports can port security be enabled on?
Manually configured access and trunk ports
What command do you use to enable port security?
switchport port-security
What command do you use to show the port security status for a specific interface?
show port-security interface int
What command do you use to set the max amount of MAC addresses allowed on a port?
switchport port-security maximum num
What is the maximum amount of MAC address a port can allow?
8192
What command do you use to set a static MAC address on a port?
switchport port-security mac-address mac
What command do you use to make dynamically learned MAC addresses stay in the configuration?
switchport port-security mac-address sticky
What command do you use to show learned MAC addresses and the ports they are on?
show port-security address
What are the types of aging with port security?
Absolute, inactivity
What is the difference between absolute and inactive aging?
Absolute removes MAC addresses after a specified amount of time, inactive removes MAC addresses after they are inactive for a set amount of time
What command do you use to set the aging time?
switchport port-security aging static time time
What command do you use to set the type of aging?
switchport port-security aging type absolute/inactivity
What command do you use to set the port security violation mode?
switchport port-security violation protect/restrict/shutdown
What must you do to an err-disabled port before enabling it?
Use the shutdown command
What command do you use to show port security settings for all ports?
show port-security
What is DHCP snooping?
Determines if DHCP messages are from a trusted or untrusted source
What interfaces are untrusted by default?
Access ports
What are typically trusted interfaces?
Trunks, configured interfaces
What command do you use to enable DHCP spoofing?
ip dhcp snooping
What command do you use on an interface you want to configure as a trusted DHCP interface?
ip dhcp snooping trust
What command do you use to limit the amount of DHCP discover messages a server can receive per second?
ip dhcp snooping limit rate
What command do you use to show DCHP snooping status?
show ip dhcp snooping
What command do you use to enable DAI on a VLAN?
ip arp inspection vlan id
What command do you use to trust an interface for DAI?
ip arp inspection trust
What command do you use to customize what DAI uses to drop ARP packets?
ip arp inspection validate src-mac/dst-mac/ip
What command do you use to enable PortFast on an interface?
spanning-tree portfast
What command do you use to enable PortFast globally on all access ports?
spanning-tree portfast default
What command do you use to re-enable a BPDU Guard enabled port?
errdisable recovery cause bpduguard
What command do you use to enable BDPU Guard on an interface?
spanning-tree bpduguard enable
What command do you use to enable BPDU Guard globally on all PortFast enabled interfaces?
spanning-tree portfast bpduguard default