【正文】
2022, Cisco Systems, Inc. All rights reserved. BCMSN — 933 PVLAN Ports and Types Private VLAN ports: ? Promiscuous: Can municate with all other ports ? Isolated: Can only municate with promiscuous ports ? Community: Can municate with other members of munity and all promiscuous ports Private VLAN types: ? Primary: Used by promiscuous ports to municate with all other ports in the private VLAN ? Isolated: Used by isolated ports to municate with promiscuous ports ? Community: Used by munity ports to municate with each other and promiscuous ports 169。 2022, Cisco Systems, Inc. All rights reserved. BCMSN — 925 Configuring PortBased Authentication Switch(config)aaa authentication dot1x {default} method1 [method2...] ? Creates an portbased authentication method list Switch(config)dot1x systemauthcontrol ? Globally enables portbased authentication Switch(config)interface type slot/port ? Enters interface configuration mode Switch(configif)dot1x portcontrol auto ? Enables portbased authentication on the interface 169。 2022, Cisco Systems, Inc. All rights reserved. BCMSN — 917 Remended Switch Security ? Set system passwords ? Configure basic ACLs ? Secure physical access to the console ? Secure access to VTYs ? Configure system warning banners ? Disable unneeded services ? SSH ? Trim CDP ? Disable the integrated HTTP daemon ? Configure basic logging ? Secure SNMP ? Limit trunking connections ? Secure the spanningtree topology 169。 2022, Cisco Systems, Inc. All rights reserved. BCMSN — 910 Network Analysis Module 169。 2 03, Cisco Systems, Inc. All rights reserved. BCMSN — 92 169。 2022, Cisco Systems, Inc. All rights reserved. BCMSN — 93 Objectives Upon pleting this lesson, you will be able to: ? Describe techniques to enhance the performance of a multilayer switched work ? Monitor switch ports using SPAN and VSPAN ? Monitor switch ports using RSPAN ? Describe the features and operation of work analysis modules on Catalyst switches to improve work traffic management ? Verify and troubleshoot the operation of work analysis modules 169。 2022, Cisco Systems, Inc. All rights reserved. BCMSN — 911 NAM Initial Configuration ? Assign parameters – IP address – Sub mask – IP broadcast address – IP host name – Default gateway – Domain name – DNS name server – SNMP (MIB variables, access control, system group settings) ? Start the web server 169。 2022, Cisco Systems, Inc. All rights reserved. BCMSN — 918 AAA Network Configuration ? Authentication – Verifies a user’s identify ? Authorization – Specifies the permitted tasks for the user ? Accounting – Provides billing, auditing, and monitoring 169。 2022, Cisco Systems, Inc. All rights reserved. BCMSN — 926 Verifying Port Security Switchshow portsecurit