【正文】
2022, Cisco Systems, Inc. All rights reserved. BCMSN — 936 Summary ? Cisco remends tasks you should plete to secure your switched work from attack. ? AAA work security services provide the primary framework through which you set up access control on a switch. ? Network access security is provided by port security and portbased authentication (). ? Use show mands to verify the configuration of port security. ? ACLs are useful for controlling access in a multilayer switched work. ? Private VLANs provide Layer 2 isolation between ports within the same private VLAN. 。 2022, Cisco Systems, Inc. All rights reserved. BCMSN — 934 Configuring Private VLANs Switch(configvlan)privatevlan [primary | isolated | munity] ? Configures a VLAN as a private VLAN Switch(configvlan)privatevlan association {secondary_vlan_list | add svl | remove svl} ? Associates secondary VLANs with the primary VLAN Switchshow vlan privatevlan type ? Verifies private VLAN configuration 169。 2022, Cisco Systems, Inc. All rights reserved. BCMSN — 932 Private VLANs 169。 2022, Cisco Systems, Inc. All rights reserved. BCMSN — 930 Configuring VACLs Switch(config)vlan accessmap map_name [seq] ? Defines a VLAN access map Switch(configaccessmap) match {ip address {1199 | 13002699 | acl_name} | ipx address {800999 | acl_name}| mac address acl_name} ? Configures the match clause in a VLAN access map sequence Switch(configaccessmap)action {drop [log]} | {forward [capture]} | {redirect {type slot/port} | {portchannel channel_id}} ? Configures the action clause in a VLAN access map sequence Switch(config)vlan filter map_name vlan_list list ? Applies the VLAN access map to the specified VLANs 169。 2022, Cisco Systems, Inc. All rights reserved. BCMSN — 928 Verifying Port Security (Cont.) Switchshow portsecurity address ? Displays MAC address table security information Switchshow portsecurity address Secure Mac Address Table Vlan Mac Address Type Ports Remaining Age (mins) 1 SecureDynamic Fa5/1 15 (I) 1 SecureDynamic Fa5/1 15 (I) 1 SecureConfigured Fa5/1 16 (I) 1 SecureConfigured Fa5/1 1 SecureConfigured Fa5/1 1 SecureConfigured Fa5/5 23 1 SecureConfigured Fa5/5 23 1 SecureConfigured Fa5/5 23 1 SecureConfigured Fa5/11 25 (I) 1 SecureConfigured Fa5/11 25 (I) Total Addresses in System: 10 Max Addresses limit in System: 128 169。 2022, Cisco Systems, Inc. All rights reserved. BCMSN — 926 Verifying Port Security Switchshow portsecurity ? Displays security information for all int